{"id":"RUSTSEC-2026-0292","summary":"Double free / use-after-free in `Chunk` and `InlineArray` removal methods when an element's `Drop` panics","details":"`Chunk::{clear, drop_left, drop_right}` and `InlineArray::{clear, truncate}` drop the removed elements before updating the metadata that records which slots hold live values — the `left`/`right` index pair for `Chunk`, the length field for `InlineArray`. If an element's `Drop` panics during the drop, that update is never reached, so the collection still treats the already-dropped elements as live. When the collection is later dropped (its destructor walks the range described by the stale metadata), or a subsequent operation touches the same slots, those elements are dropped a second time — a double free (CWE-415) / use-after-free (CWE-416) reachable from safe Rust.\n\nThe stale field is `left` and `right` for `Chunk::clear`, `left` for `drop_left`, `right` for `drop_right`, and the length field for both `InlineArray` methods.\n\n## Mitigation\n\nUpgrade to `imbl-sized-chunks` 0.2.0 or later, which commits the metadata before dropping any element (fixed in jneem/imbl-sized-chunks#14, released in 0.2.0).","modified":"2026-09-21T09:15:02.898993962Z","published":"2026-09-04T12:00:00Z","database_specific":{"license":"CC0-1.0"},"references":[{"type":"PACKAGE","url":"https://crates.io/crates/imbl-sized-chunks"},{"type":"ADVISORY","url":"https://rustsec.org/advisories/RUSTSEC-2026-0292.html"},{"type":"WEB","url":"https://github.com/jneem/imbl-sized-chunks/pull/14"}],"affected":[{"package":{"name":"imbl-sized-chunks","ecosystem":"crates.io","purl":"pkg:cargo/imbl-sized-chunks"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.0.0-0"},{"fixed":"0.2.0"}]}],"ecosystem_specific":{"affects":{"arch":[],"os":[],"functions":["imbl_sized_chunks::inline_array::InlineArray::clear","imbl_sized_chunks::inline_array::InlineArray::truncate","imbl_sized_chunks::sized_chunk::Chunk::clear","imbl_sized_chunks::sized_chunk::Chunk::drop_left","imbl_sized_chunks::sized_chunk::Chunk::drop_right"]},"affected_functions":null},"database_specific":{"informational":null,"source":"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0292.json","categories":["memory-corruption"],"cvss":null}}],"schema_version":"1.9.0"}