Home

Description

Double-Free / Use-After-Free (UAF) in the `IntoIter::drop` and `ThinVec::clear` functions in the thin_vec crate. A panic in `ptr::drop_in_place` skips setting the length to zero.

PUBLISHED Reserved 2026-04-20 | Published 2026-04-20 | Updated 2026-04-20 | Assigner mozilla

Product status

Default status
unknown

0.2.16 (rpm)
unaffected

Credits

Juhyung Son finder

References

github.com/...in-vec/security/advisories/GHSA-xphw-cqx3-667j

cve.org (CVE-2026-6654)

nvd.nist.gov (CVE-2026-6654)

Download JSON