- Reported
-
- Issued
-
- Package
-
owned-alloc
(crates.io)
- Type
-
Vulnerability
- Categories
-
- Keywords
-
#panic-safety
#memory-safety
#use-after-free
#double-free
- References
-
- Patched
-
no patched versions
- Affected Functions
- Version
owned_alloc::MaybeUninitAlloc::drop_in_place
-
owned_alloc::OwnedAlloc::drop_in_place
-
Description
OwnedAlloc::drop_in_place destroys the contained value by hand, then commits
the ownership transfer with mem::forget(self) — which lives inside into_raw
and so runs only after the destruction. T::drop is user code and may panic. If
it does, the forget is skipped and the still-live OwnedAlloc unwinds, whose
destructor drops the same T a second time and then deallocates. For a T that
owns an allocation, the same block is freed twice — a double free (CWE-415).
That destructor also reads the already-destroyed value through
Layout::for_value before deallocating, a use-after-free (CWE-416).
MaybeUninitAlloc::drop_in_place delegates to the same function, so both public
entry points are affected. Storing a value whose Drop can panic and calling
either is enough — no unsafe on the caller's side.
Fix
No fixed release is available. The crate has had no release since 2018 and the
maintainer has not responded to the report, nor to the one on lockfree, which
is published from the same account. forget_inner leaks the value instead of
destroying it, which is safe.
Advisory available under CC0-1.0
license.