VDB
DEBIAN-CVE-2026-6654
DEBIAN-CVE-2026-6654
PUBLISHED
CVSS 5.099999904632568 MEDIUM
Double-Free / Use-After-Free (UAF) in the `IntoIter::drop` and `ThinVec::clear` functions in the thin_vec crate. A panic in `ptr::drop_in_place` skips setting the length to zero.
Risk Scores
CVSS 3.1
5.099999904632568
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:14 | rust-thin-vec | 0.2.13-2, 0, 0.2.13-2 |
| Debian:13 | rust-thin-vec | 0.2.13-2, 0.2.17-1, 0 |
| Debian | rust-thin-vec |
Timeline
- Apr 20, 2026 CVE Published
- May 4, 2026 CVE Updated