RustSec logo

HistoryEditJSON (OSV)

RUSTSEC-2026-0293

Double free / use-after-free in Consumer::skip and Consumer::clear when an element's Drop panics

Reported
Issued
Package
ringbuf (crates.io)
Type
Vulnerability
Categories
Keywords
#memory-safety #double-free #use-after-free #panic-safety
References
Patched
  • >=0.5.2
Affected Functions
Version
ringbuf::traits::consumer::Consumer::clear
  • <0.5.2
ringbuf::traits::consumer::Consumer::skip
  • <0.5.2

Description

Consumer::skip() and Consumer::clear() are not panic-safe. They drop the consumed elements in place and only afterwards call advance_read_index() to move the ring buffer's read index past them. If an element's Drop panics mid-loop, advance_read_index() is never reached, so the read index still points at the already-dropped elements. When the ring buffer is later dropped, its destructor re-visits those slots and drops the same elements a second time — a double free (CWE-415) / use-after-free (CWE-416) reachable from safe Rust, confirmed under AddressSanitizer.

Consumer::clear() delegates to Consumer::skip(self.len()), so both share the same root cause and the same fix.

Mitigation

Update to 0.5.2 or later (fixed in agerasev/ringbuf#60).

Advisory available under CC0-1.0 license.