CVE-2026-6654 PUBLISHED

Use-After-Free and Double-Free in IntoIter::drop when element drop panics

Assigner: mozilla
Reserved: 20.04.2026 Published: 20.04.2026 Updated: 20.04.2026

Double-Free / Use-After-Free (UAF) in the IntoIter::drop and ThinVec::clear functions in the thin_vec crate. A panic in ptr::drop_in_place skips setting the length to zero.

Product Status

Vendor Mozilla
Product thin-vec
Versions Default: unknown
  • unaffected from 0.2.16 to * (incl.)

Credits

  • Juhyung Son finder

References