rustsec-2026-0300
osv_rustsec`SkipList::clear` drops the node chain and only then resets `tail` and `len`. The drop runs each element's `Drop`, and `T` carries no bounds excluding a panicking one. If it unwinds, `tail` still points at the freed node while `len` stays non-zero. `back()`, `back_mut()`, `last_key_value()` and `last()` dereference `tail` through `unsafe`, so reading the container after the unwind is a use-after-free (CWE-416). `Drop for SkipList` calls `Box::from_raw` on `self.head`, which `clear` already destroyed, so dropping the container is a double free (CWE-415). `retain`, `retain_mut` and `dedup_by` reach the same state through `Node::filter_rebuild`, which frees nodes and runs a user predicate before the caller commits `tail` and `len`. There the head links are left partially rewired, so traversal can also reach freed nodes. ## Mitigation Update to 1.1.1.
- Published
- unknown
- Last Modified
- unknown
CVSS details not available.
No product information available.
No linked vulnerabilities found.
{
"affected": [
{
"database_specific": {
"categories": [
"memory-corruption"
],
"cvss": null,
"informational": null,
"source": "https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0300.json"
},
"ecosystem_specific": {
"affected_functions": null,
"affects": {
"arch": [],
"functions": [
"skiplist::ordered_skip_list::OrderedSkipList::clear",
"skiplist::ordered_skip_list::OrderedSkipList::dedup_by",
"skiplist::ordered_skip_list::OrderedSkipList::retain",
"skiplist::skip_list::SkipList::clear",
"skiplist::skip_list::SkipList::dedup_by",
"skiplist::skip_list::SkipList::retain",
"skiplist::skip_list::SkipList::retain_mut",
"skiplist::skip_map::SkipMap::clear",
"skiplist::skip_map::SkipMap::retain"
],
"os": []
}
},
"package": {
"ecosystem": "crates.io",
"name": "skiplist",
"purl": "pkg:cargo/skiplist"
},
"ranges": [
{
"events": [
{
"introduced": "0.0.0-0"
},
{
"fixed": "1.1.1"
}
],
"type": "SEMVER"
}
]
}
],
"aliases": [
"GHSA-x6j6-3ffp-qrfr"
],
"database_specific": {
"license": "CC0-1.0"
},
"details": "`SkipList::clear` drops the node chain and only then resets `tail` and `len`.\nThe drop runs each element's `Drop`, and `T` carries no bounds excluding a\npanicking one. If it unwinds, `tail` still points at the freed node while `len`\nstays non-zero.\n\n`back()`, `back_mut()`, `last_key_value()` and `last()` dereference `tail`\nthrough `unsafe`, so reading the container after the unwind is a use-after-free\n(CWE-416). `Drop for SkipList` calls `Box::from_raw` on `self.head`, which\n`clear` already destroyed, so dropping the container is a double free\n(CWE-415).\n\n`retain`, `retain_mut` and `dedup_by` reach the same state through\n`Node::filter_rebuild`, which frees nodes and runs a user predicate before the\ncaller commits `tail` and `len`. There the head links are left partially\nrewired, so traversal can also reach freed nodes.\n\n## Mitigation\n\nUpdate to 1.1.1.",
"id": "RUSTSEC-2026-0300",
"modified": "2026-09-22T07:45:03.895629896Z",
"published": "2026-09-02T12:00:00Z",
"references": [
{
"type": "PACKAGE",
"url": "https://crates.io/crates/skiplist"
},
{
"type": "ADVISORY",
"url": "https://rustsec.org/advisories/RUSTSEC-2026-0300.html"
},
{
"type": "WEB",
"url": "https://github.com/JP-Ellis/rust-skiplist/pull/334"
}
],
"schema_version": "1.9.0",
"summary": "Use-after-free in `clear` and `retain` when an element's `Drop` panics"
}