---
id: RUSTSEC-2026-0293
title: >-
  Double free / use-after-free in `Consumer::skip` and `Consumer::clear` when an
  element's `Drop` panics
summary: >-
  Double free / use-after-free in `Consumer::skip` and `Consumer::clear` when an
  element's `Drop` panics
severity: none
vendor: ringbuf
product: ringbuf
ecosystem: rust
affected:
  - 'ringbuf >= 0.0.0-0, < 0.5.2'
patched:
  - ringbuf 0.5.2
published: '2026-09-21'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T09:15:02.895664200Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/RUSTSEC-2026-0293'
references:
  - url: 'https://crates.io/crates/ringbuf'
  - url: 'https://rustsec.org/advisories/RUSTSEC-2026-0293.html'
  - url: 'https://github.com/agerasev/ringbuf/pull/60'
tags:
  - osv
  - rust
ingestedAt: '2026-09-21T16:06:16.786Z'
---

## Overview

`Consumer::skip()` and `Consumer::clear()` are not panic-safe. They drop the
consumed elements in place and only afterwards call `advance_read_index()` to move
the ring buffer's read index past them. If an element's `Drop` panics mid-loop,
`advance_read_index()` is never reached, so the read index still points at the
already-dropped elements. When the ring buffer is later dropped, its destructor
re-visits those slots and drops the same elements a second time — a double free
(CWE-415) / use-after-free (CWE-416) reachable from safe Rust, confirmed under
AddressSanitizer.

`Consumer::clear()` delegates to `Consumer::skip(self.len())`, so both share the
same root cause and the same fix.

## Mitigation

Update to 0.5.2 or later (fixed in agerasev/ringbuf#60).

## Affected packages

- `ringbuf >= 0.0.0-0, < 0.5.2`

## Remediation

Upgrade to a patched release:

- `ringbuf 0.5.2`
