VDB

DEBIAN-CVE-2026-6654

DEBIAN-CVE-2026-6654 PUBLISHED CVSS 5.099999904632568 MEDIUM

Double-Free / Use-After-Free (UAF) in the `IntoIter::drop` and `ThinVec::clear` functions in the thin_vec crate. A panic in `ptr::drop_in_place` skips setting the length to zero.

Risk Scores

CVSS 3.1
5.099999904632568
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersions
Debian:14rust-thin-vec0.2.13-2, 0, 0.2.13-2
Debian:13rust-thin-vec0.2.13-2, 0.2.17-1, 0
Debianrust-thin-vec

Timeline

  • Apr 20, 2026 CVE Published
  • May 4, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›