Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
38 changes: 38 additions & 0 deletions crates/aligned_box/RUSTSEC-0000-0000.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
```toml
[advisory]
id = "RUSTSEC-0000-0000"
package = "aligned_box"
date = "2026-09-09"
url = "https://github.com/michaellass/aligned_box/pull/6"
categories = ["memory-corruption"]
keywords = ["memory-safety", "double-free", "use-after-free", "panic-safety"]

[affected.functions]
"aligned_box::AlignedBox::realloc_with_default" = ["< 0.3.1"]

[versions]
patched = [">= 0.3.1"]
```

# Double free in `AlignedBox<[T]>::realloc_with_default` when an element's `Drop` panics

Shrinking an `AlignedBox<[T]>` takes ownership of the buffer out of
`self.container` with `ManuallyDrop::take`, destroys the elements past the new
length, and only then commits the new `Box` back into `self.container`.
`ManuallyDrop::take` moves ownership but not the bits, so until that commit
`self.container` still points at the original buffer.

`T::drop` runs inside the destruction loop and is user code — `T` carries no
bound that would exclude a panicking `Drop`. If it unwinds, the commit is
skipped and `self.container` is left pointing at the buffer whose tail has
already been destroyed. `AlignedBox`'s own destructor then reconstructs a `Box`
from that pointer, drops every element again and deallocates — a double free
(CWE-415) / use-after-free (CWE-416) reachable from safe Rust.

Growing the slice destroys nothing and is unaffected, as is
`realloc_with_value`, which requires `T: Copy` and therefore a `Drop` that
cannot run.

## Mitigation

Update to 0.3.1.