RUSTSEC-2026-0300None▾ SunlitUse-after-free in `clear` and `retain` when an element's `Drop` panics
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
SkipList::clear drops the node chain and only then resets tail and len.
The drop runs each element's Drop, and T carries no bounds excluding a
panicking one. If it unwinds, tail still points at the freed node while len
stays non-zero.
back(), back_mut(), last_key_value() and last() dereference tail
through unsafe, so reading the container after the unwind is a use-after-free
(CWE-416). Drop for SkipList calls Box::from_raw on self.head, which
clear already destroyed, so dropping the container is a double free
(CWE-415).
retain, retain_mut and dedup_by reach the same state through
Node::filter_rebuild, which frees nodes and runs a user predicate before the
caller commits tail and len. There the head links are left partially
rewired, so traversal can also reach freed nodes.
Update to 1.1.1.
skiplist >= 0.0.0-0, < 1.1.1Upgrade to a patched release:
skiplist 1.1.1