{"id":"RUSTSEC-2026-0293","summary":"Double free / use-after-free in `Consumer::skip` and `Consumer::clear` when an element's `Drop` panics","details":"`Consumer::skip()` and `Consumer::clear()` are not panic-safe. They drop the\nconsumed elements in place and only afterwards call `advance_read_index()` to move\nthe ring buffer's read index past them. If an element's `Drop` panics mid-loop,\n`advance_read_index()` is never reached, so the read index still points at the\nalready-dropped elements. When the ring buffer is later dropped, its destructor\nre-visits those slots and drops the same elements a second time — a double free\n(CWE-415) / use-after-free (CWE-416) reachable from safe Rust, confirmed under\nAddressSanitizer.\n\n`Consumer::clear()` delegates to `Consumer::skip(self.len())`, so both share the\nsame root cause and the same fix.\n\n## Mitigation\n\nUpdate to 0.5.2 or later (fixed in agerasev/ringbuf#60).","modified":"2026-09-21T09:15:02.895664200Z","published":"2026-09-21T12:00:00Z","database_specific":{"license":"CC0-1.0"},"references":[{"type":"PACKAGE","url":"https://crates.io/crates/ringbuf"},{"type":"ADVISORY","url":"https://rustsec.org/advisories/RUSTSEC-2026-0293.html"},{"type":"WEB","url":"https://github.com/agerasev/ringbuf/pull/60"}],"affected":[{"package":{"name":"ringbuf","ecosystem":"crates.io","purl":"pkg:cargo/ringbuf"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.0.0-0"},{"fixed":"0.5.2"}]}],"ecosystem_specific":{"affected_functions":null,"affects":{"functions":["ringbuf::traits::consumer::Consumer::clear","ringbuf::traits::consumer::Consumer::skip"],"arch":[],"os":[]}},"database_specific":{"informational":null,"source":"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0293.json","categories":["memory-corruption"],"cvss":null}}],"schema_version":"1.9.0"}