Double-Free / Use-After-Free (UAF) in the IntoIter::drop and ThinVec::clear functions in the thin_vec crate. A panic in ptr::drop_in_place skips setting the length to zero.
IntoIter::drop
ThinVec::clear
ptr::drop_in_place
{ "binaries": [ { "binary_version": "0.2.13-1", "binary_name": "librust-thin-vec-dev" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-6654.json"
{ "binaries": [ { "binary_version": "0.2.13-2", "binary_name": "librust-thin-vec-dev" } ] }