---
id: RUSTSEC-2026-0292
title: >-
  Double free / use-after-free in `Chunk` and `InlineArray` removal methods when
  an element's `Drop` panics
summary: >-
  Double free / use-after-free in `Chunk` and `InlineArray` removal methods when
  an element's `Drop` panics
severity: none
vendor: imbl-sized-chunks
product: imbl-sized-chunks
ecosystem: rust
affected:
  - 'imbl-sized-chunks >= 0.0.0-0, < 0.2.0'
patched:
  - imbl-sized-chunks 0.2.0
published: '2026-09-04'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T09:15:02.898993962Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/RUSTSEC-2026-0292'
references:
  - url: 'https://crates.io/crates/imbl-sized-chunks'
  - url: 'https://rustsec.org/advisories/RUSTSEC-2026-0292.html'
  - url: 'https://github.com/jneem/imbl-sized-chunks/pull/14'
tags:
  - osv
  - rust
ingestedAt: '2026-09-21T16:06:16.786Z'
---

## Overview

`Chunk::{clear, drop_left, drop_right}` and `InlineArray::{clear, truncate}` drop the removed elements before updating the metadata that records which slots hold live values — the `left`/`right` index pair for `Chunk`, the length field for `InlineArray`. If an element's `Drop` panics during the drop, that update is never reached, so the collection still treats the already-dropped elements as live. When the collection is later dropped (its destructor walks the range described by the stale metadata), or a subsequent operation touches the same slots, those elements are dropped a second time — a double free (CWE-415) / use-after-free (CWE-416) reachable from safe Rust.

The stale field is `left` and `right` for `Chunk::clear`, `left` for `drop_left`, `right` for `drop_right`, and the length field for both `InlineArray` methods.

## Mitigation

Upgrade to `imbl-sized-chunks` 0.2.0 or later, which commits the metadata before dropping any element (fixed in jneem/imbl-sized-chunks#14, released in 0.2.0).

## Affected packages

- `imbl-sized-chunks >= 0.0.0-0, < 0.2.0`

## Remediation

Upgrade to a patched release:

- `imbl-sized-chunks 0.2.0`
