RUSTSEC-2026-0282None▾ SunlitDouble free in `AlignedBox<[T]>::realloc_with_default` when an element's `Drop` panics
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Shrinking an AlignedBox<[T]> takes ownership of the buffer out of
self.container with ManuallyDrop::take, destroys the elements past the new
length, and only then commits the new Box back into self.container.
ManuallyDrop::take moves ownership but not the bits, so until that commit
self.container still points at the original buffer.
T::drop runs inside the destruction loop and is user code — T carries no
bound that would exclude a panicking Drop. If it unwinds, the commit is
skipped and self.container is left pointing at the buffer whose tail has
already been destroyed. AlignedBox's own destructor then reconstructs a Box
from that pointer, drops every element again and deallocates — a double free
(CWE-415) / use-after-free (CWE-416) reachable from safe Rust.
Growing the slice destroys nothing and is unaffected, as is
realloc_with_value, which requires T: Copy and therefore a Drop that
cannot run.
Update to 0.3.1.
aligned_box >= 0.0.0-0, < 0.3.1Upgrade to a patched release:
aligned_box 0.3.1