{"id":"RUSTSEC-2026-0267","aliases":["GHSA-mr2v-63pc-gmr4"],"title":"Panic-safety unsoundness in `BitVecCore::clear` (double-free / use-after-free)","summary":"Panic-safety unsoundness in `BitVecCore::clear` (double-free / use-after-free)","severity":"none","vendor":"stable-vec","product":"stable-vec","ecosystem":"rust","affected":["stable-vec >= 0.0.0-0, < 0.4.3"],"patched":["stable-vec 0.4.3"],"published":"2026-08-24","updated":"2026-08-25","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/RUSTSEC-2026-0267","references":[{"url":"https://crates.io/crates/stable-vec"},{"url":"https://rustsec.org/advisories/RUSTSEC-2026-0267.html"},{"url":"https://github.com/LukasKalbertodt/stable-vec/pull/51"}],"tags":["osv","rust"],"ingestedAt":"2026-08-25T19:26:23.849Z","slug":"RUSTSEC-2026-0267","body":"## Overview\n\n`BitVecCore::clear` drops every occupied element with `drop_in_place` and only\nafterwards clears the occupancy bits and resets `len`. If an element's `Drop`\npanics, those metadata updates are skipped, so the slot of the already-dropped\nelement stays marked as occupied. `BitVecCore::drop` calls `clear()` again,\nvisits the same slot, and drops the element a second time — a double-free /\nuse-after-free reachable from safe Rust.\n\nReachable via the public `StableVec::clear` and `ExternStableVec::clear`, which\ndelegate to `BitVecCore::clear`.\n\n## Impact\n\n* CWE-415 (Double Free): the same allocation is freed twice.\n* CWE-416 (Use-After-Free): a freed allocation is accessed during a repeated `Drop`.\n\nReachable entirely from safe Rust via `catch_unwind` with element types whose\n`Drop` can panic. Confirmed under AddressSanitizer on 0.4.2.\n\n## Fix\n\nFixed in `stable-vec` 0.4.3 by removing each element via `remove_at`, which\nclears the occupancy bit before taking the value out.\n\nRelease 0.4.3 also fixes several other panic-safety issues found by the\nmaintainer; see [GHSA-mr2v-63pc-gmr4](https://github.com/LukasKalbertodt/stable-vec/security/advisories/GHSA-mr2v-63pc-gmr4)\nand the 0.4.3 changelog for the full list.\n\n## Affected packages\n\n- `stable-vec >= 0.0.0-0, < 0.4.3`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `stable-vec 0.4.3`","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}