RUSTSEC-2026-0293

Source
https://rustsec.org/advisories/RUSTSEC-2026-0293
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0293.json
JSON Data
https://api.test.osv.dev/v1/vulns/RUSTSEC-2026-0293
Published
2026-09-21T12:00:00Z
Modified
2026-09-21T09:15:02Z
Summary
Double free / use-after-free in `Consumer::skip` and `Consumer::clear` when an element's `Drop` panics
Details

Consumer::skip() and Consumer::clear() are not panic-safe. They drop the consumed elements in place and only afterwards call advance_read_index() to move the ring buffer's read index past them. If an element's Drop panics mid-loop, advance_read_index() is never reached, so the read index still points at the already-dropped elements. When the ring buffer is later dropped, its destructor re-visits those slots and drops the same elements a second time — a double free (CWE-415) / use-after-free (CWE-416) reachable from safe Rust, confirmed under AddressSanitizer.

Consumer::clear() delegates to Consumer::skip(self.len()), so both share the same root cause and the same fix.

Mitigation

Update to 0.5.2 or later (fixed in agerasev/ringbuf#60).

Database specific
{
    "license":  "CC0-1.0"
}
References

Affected packages

crates.io / ringbuf

Package

Name
ringbuf
View open source insights on deps.dev
Purl
pkg:cargo/ringbuf

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0-0
Fixed
0.5.2

Ecosystem specific

{
    "affected_functions":  null,
    "affects":  {
        "arch":  [],
        "functions":  [
            "ringbuf::traits::consumer::Consumer::clear",
            "ringbuf::traits::consumer::Consumer::skip"
        ],
        "os":  []
    }
}

Database specific

categories
[
    "memory-corruption"
]
cvss
null
informational
null
source
"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0293.json"