RustSec logo

HistoryEditJSON (OSV)

RUSTSEC-2026-0282

Double free in AlignedBox<[T]>::realloc_with_default when an element's Drop panics

Reported
Issued
Package
aligned_box (crates.io)
Type
Vulnerability
Categories
Keywords
#memory-safety #double-free #use-after-free #panic-safety
References
Patched
  • >=0.3.1
Affected Functions
Version
aligned_box::AlignedBox::realloc_with_default
  • <0.3.1

Description

Shrinking an AlignedBox<[T]> takes ownership of the buffer out of self.container with ManuallyDrop::take, destroys the elements past the new length, and only then commits the new Box back into self.container. ManuallyDrop::take moves ownership but not the bits, so until that commit self.container still points at the original buffer.

T::drop runs inside the destruction loop and is user code — T carries no bound that would exclude a panicking Drop. If it unwinds, the commit is skipped and self.container is left pointing at the buffer whose tail has already been destroyed. AlignedBox's own destructor then reconstructs a Box from that pointer, drops every element again and deallocates — a double free (CWE-415) / use-after-free (CWE-416) reachable from safe Rust.

Growing the slice destroys nothing and is unaffected, as is realloc_with_value, which requires T: Copy and therefore a Drop that cannot run.

Mitigation

Update to 0.3.1.

Advisory available under CC0-1.0 license.