{"id":"RUSTSEC-2026-0152","aliases":["GHSA-q95x-7g78-rccv"],"title":"Use-after-free","summary":"Use-after-free","severity":"none","vendor":"oneringbuf","product":"oneringbuf","ecosystem":"rust","affected":["oneringbuf >= 0.0.0-0, < 0.8.0"],"patched":["oneringbuf 0.8.0"],"published":"2026-05-27","updated":"2026-07-09","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/RUSTSEC-2026-0152","references":[{"url":"https://crates.io/crates/oneringbuf"},{"url":"https://rustsec.org/advisories/RUSTSEC-2026-0152.html"},{"url":"https://github.com/skilvingr/rust-oneringbuf/commit/643a24b30914068416dff9021a069c12c865a316"},{"url":"https://github.com/skilvingr/rust-oneringbuf/commit/643a24b30914068416dff9021a069c12c865a316"}],"tags":["osv","rust"],"ingestedAt":"2026-07-09T18:56:37.352Z","slug":"RUSTSEC-2026-0152","body":"## Overview\n\nAffected versions of `oneringbuf` exposed the obsolete `IntoRef::into_ref` method through the public `IntoRef` trait. For heap-backed ring buffers, this method returned a `DroppableRef` handle.\n\n`DroppableRef` stored an owning raw pointer created from `Box::into_raw`. Its `Clone` implementation copied this raw pointer without incrementing the internal `alive_iters` counter. Internally, this clone pattern appears to rely on a fixed number of handles being created to match the initial `alive_iters` value. However, exposing `DroppableRef` through the public `IntoRef::TargetRef` associated type allows safe external code to create additional clones beyond that fixed count, breaking the lifetime protocol. `Drop` later dereferenced the pointer and could free the backing allocation with `Box::from_raw`.\n\nSafe code could call `IntoRef::into_ref` to obtain a `DroppableRef` and then clone it. Each clone pointed to the same allocation, but the internal `alive_iters` counter was not increased. As a result, one clone could free the allocation while another clone still existed. Dropping the remaining clone then accessed freed memory, causing a heap-use-after-free.\n\nThe issue was fixed in version 0.8.0 by removing the obsolete `into_ref` method.\n\n## Trigger\n\n```rust\nuse oneringbuf::{IntoRef, LocalHeapRB};\n\nfn main() {\n    let rb = LocalHeapRB::<usize>::from(vec![1, 2, 3]);\n\n    let r = <LocalHeapRB<usize> as IntoRef>::into_ref(rb);\n    let r2 = r.clone();\n    let r3 = r.clone();\n\n    drop(r);\n    drop(r2);\n    drop(r3); // AddressSanitizer: heap-use-after-free\n}\n```\n\n## Affected packages\n\n- `oneringbuf >= 0.0.0-0, < 0.8.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `oneringbuf 0.8.0`","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}