{"id":"GHSA-q95x-7g78-rccv","summary":"OneRingBuf has a Use After Free Vulnerability","details":"Affected versions of `oneringbuf` exposed the obsolete `IntoRef::into_ref` method through the public `IntoRef` trait. For heap-backed ring buffers, this method returned a `DroppableRef` handle.\n\n`DroppableRef` stored an owning raw pointer created from `Box::into_raw`. Its `Clone` implementation copied this raw pointer without incrementing the internal `alive_iters` counter. Internally, this clone pattern appears to rely on a fixed number of handles being created to match the initial `alive_iters` value. However, exposing `DroppableRef` through the public `IntoRef::TargetRef` associated type allows safe external code to create additional clones beyond that fixed count, breaking the lifetime protocol. `Drop` later dereferenced the pointer and could free the backing allocation with `Box::from_raw`.\n\nSafe code could call `IntoRef::into_ref` to obtain a `DroppableRef` and then clone it. Each clone pointed to the same allocation, but the internal `alive_iters` counter was not increased. As a result, one clone could free the allocation while another clone still existed. Dropping the remaining clone then accessed freed memory, causing a heap-use-after-free.\n\nThe issue was fixed in version 0.8.0 by removing the obsolete `into_ref` method.\n\n## Trigger\n\n```rust\nuse oneringbuf::{IntoRef, LocalHeapRB};\n\nfn main() {\n    let rb = LocalHeapRB::\u003cusize\u003e::from(vec![1, 2, 3]);\n\n    let r = \u003cLocalHeapRB\u003cusize\u003e as IntoRef\u003e::into_ref(rb);\n    let r2 = r.clone();\n    let r3 = r.clone();\n\n    drop(r);\n    drop(r2);\n    drop(r3); // AddressSanitizer: heap-use-after-free\n}\n```","aliases":["RUSTSEC-2026-0152"],"modified":"2026-07-09T06:56:37.198846378Z","published":"2026-07-08T20:26:23Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-07-08T20:26:23Z","nvd_published_at":null,"cwe_ids":["CWE-416"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/skilvingr/rust-oneringbuf/commit/643a24b30914068416dff9021a069c12c865a316"},{"type":"PACKAGE","url":"https://github.com/Skilvingr/rust-oneringbuf"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2026-0152.html"}],"affected":[{"package":{"name":"oneringbuf","ecosystem":"crates.io","purl":"pkg:cargo/oneringbuf"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.8.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-q95x-7g78-rccv/GHSA-q95x-7g78-rccv.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}]}