Skip to content

RUSTSEC-2026-0293: Double free / use-after-free in Consumer::skip and Consumer::clear when an element's Drop panics #125

Description

@github-actions

Double free / use-after-free in Consumer::skip and Consumer::clear when an element's Drop panics

Details
Package ringbuf
Version 0.5.1
URL agerasev/ringbuf#60
Date 2026-09-21
Patched versions >=0.5.2

Consumer::skip() and Consumer::clear() are not panic-safe. They drop the
consumed elements in place and only afterwards call advance_read_index() to move
the ring buffer's read index past them. If an element's Drop panics mid-loop,
advance_read_index() is never reached, so the read index still points at the
already-dropped elements. When the ring buffer is later dropped, its destructor
re-visits those slots and drops the same elements a second time — a double free
(CWE-415) / use-after-free (CWE-416) reachable from safe Rust, confirmed under
AddressSanitizer.

Consumer::clear() delegates to Consumer::skip(self.len()), so both share the
same root cause and the same fix.

Mitigation

Update to 0.5.2 or later (fixed in agerasev/ringbuf#60).

See advisory page for additional details.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions