From b7afa85ecb2fb91a1b1e2b71136d56935cdfcdf5 Mon Sep 17 00:00:00 2001 From: tooson9010-spec Date: Wed, 9 Sep 2026 09:13:33 +0900 Subject: [PATCH] Add advisory for aligned_box --- crates/aligned_box/RUSTSEC-0000-0000.md | 38 +++++++++++++++++++++++++ 1 file changed, 38 insertions(+) create mode 100644 crates/aligned_box/RUSTSEC-0000-0000.md diff --git a/crates/aligned_box/RUSTSEC-0000-0000.md b/crates/aligned_box/RUSTSEC-0000-0000.md new file mode 100644 index 000000000..d88bde2ce --- /dev/null +++ b/crates/aligned_box/RUSTSEC-0000-0000.md @@ -0,0 +1,38 @@ +```toml +[advisory] +id = "RUSTSEC-0000-0000" +package = "aligned_box" +date = "2026-09-09" +url = "https://github.com/michaellass/aligned_box/pull/6" +categories = ["memory-corruption"] +keywords = ["memory-safety", "double-free", "use-after-free", "panic-safety"] + +[affected.functions] +"aligned_box::AlignedBox::realloc_with_default" = ["< 0.3.1"] + +[versions] +patched = [">= 0.3.1"] +``` + +# Double free in `AlignedBox<[T]>::realloc_with_default` when an element's `Drop` panics + +Shrinking an `AlignedBox<[T]>` takes ownership of the buffer out of +`self.container` with `ManuallyDrop::take`, destroys the elements past the new +length, and only then commits the new `Box` back into `self.container`. +`ManuallyDrop::take` moves ownership but not the bits, so until that commit +`self.container` still points at the original buffer. + +`T::drop` runs inside the destruction loop and is user code — `T` carries no +bound that would exclude a panicking `Drop`. If it unwinds, the commit is +skipped and `self.container` is left pointing at the buffer whose tail has +already been destroyed. `AlignedBox`'s own destructor then reconstructs a `Box` +from that pointer, drops every element again and deallocates — a double free +(CWE-415) / use-after-free (CWE-416) reachable from safe Rust. + +Growing the slice destroys nothing and is unaffected, as is +`realloc_with_value`, which requires `T: Copy` and therefore a `Drop` that +cannot run. + +## Mitigation + +Update to 0.3.1.