Double free / use-after-free in Consumer::skip and Consumer::clear when an element's Drop panics
| Details |
|
| Package |
ringbuf |
| Version |
0.5.1 |
| URL |
agerasev/ringbuf#60 |
| Date |
2026-09-21 |
| Patched versions |
>=0.5.2 |
Consumer::skip() and Consumer::clear() are not panic-safe. They drop the
consumed elements in place and only afterwards call advance_read_index() to move
the ring buffer's read index past them. If an element's Drop panics mid-loop,
advance_read_index() is never reached, so the read index still points at the
already-dropped elements. When the ring buffer is later dropped, its destructor
re-visits those slots and drops the same elements a second time — a double free
(CWE-415) / use-after-free (CWE-416) reachable from safe Rust, confirmed under
AddressSanitizer.
Consumer::clear() delegates to Consumer::skip(self.len()), so both share the
same root cause and the same fix.
Mitigation
Update to 0.5.2 or later (fixed in agerasev/ringbuf#60).
See advisory page for additional details.
ringbuf0.5.1>=0.5.2Consumer::skip()andConsumer::clear()are not panic-safe. They drop theconsumed elements in place and only afterwards call
advance_read_index()to movethe ring buffer's read index past them. If an element's
Droppanics mid-loop,advance_read_index()is never reached, so the read index still points at thealready-dropped elements. When the ring buffer is later dropped, its destructor
re-visits those slots and drops the same elements a second time — a double free
(CWE-415) / use-after-free (CWE-416) reachable from safe Rust, confirmed under
AddressSanitizer.
Consumer::clear()delegates toConsumer::skip(self.len()), so both share thesame root cause and the same fix.
Mitigation
Update to 0.5.2 or later (fixed in agerasev/ringbuf#60).
See advisory page for additional details.