RUSTSEC-2026-0282
Dashboard / Vulnerabilities / RUSTSEC-2026-0282
RUSTSEC-2026-0282
Summary: Double free in `AlignedBox<[T]>::realloc_with_default` when an element's `Drop` panics
Details: Shrinking an `AlignedBox<[T]>` takes ownership of the buffer out of `self.container` with `ManuallyDrop::take`, destroys the elements past the new length, and only then commits the new `Box` back into `self.container`. `ManuallyDrop::take` moves ownership but not the bits, so until that commit `self.container` still points at the original buffer. `T::drop` runs inside the destruction loop and is user code — `T` carries no bound that would exclude a panicking `Drop`. If it unwinds, the commit is skipped and `self.container` is left pointing at the buffer whose tail has already been destroyed. `AlignedBox`'s own destructor then reconstructs a `Box` from that pointer, drops every element again and deallocates — a double free (CWE-415) / use-after-free (CWE-416) reachable from safe Rust. Growing the slice destroys nothing and is unaffected, as is `realloc_with_value`, which requires `T: Copy` and therefore a `Drop` that cannot run. ## Mitigation Update to 0.3.1.
References: https://crates.io/crates/aligned_box, https://rustsec.org/advisories/RUSTSEC-2026-0282.html, https://github.com/michaellass/aligned_box/pull/6
Affected packages
Package
Name: aligned_box
Purl: pkg:cargo/aligned_box
Affected ranges
Type: SEMVER
Events:
