Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-6654

Опубликовано: 20 апр. 2026
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

Double-Free / Use-After-Free (UAF) in the IntoIter::drop and ThinVec::clear functions in the thin_vec crate. A panic in ptr::drop_in_place skips setting the length to zero.

A flaw was found in the thin_vec component of mozilla/thin-vec. This vulnerability involves a memory management error known as a Double-Free/Use-After-Free (UAF), which occurs in the IntoIter::drop and ThinVec::clear functions. When a specific error condition (a panic in ptr::drop_in_place) is triggered, the system fails to correctly manage memory, potentially allowing an attacker to execute malicious code or cause the application to crash, leading to a denial of service.

Отчет

This vulnerability affects version 0.2.15 of thin-vec, which is not included in any Red Hat products.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10firefoxNot affected
Red Hat Enterprise Linux 10gjsNot affected
Red Hat Enterprise Linux 10rustNot affected
Red Hat Enterprise Linux 10thunderbirdNot affected
Red Hat Enterprise Linux 7firefoxNot affected
Red Hat Enterprise Linux 8firefoxNot affected
Red Hat Enterprise Linux 8rust-toolset:rhel8/rustNot affected
Red Hat Enterprise Linux 8thunderbirdNot affected
Red Hat Enterprise Linux 9firefoxNot affected
Red Hat Enterprise Linux 9gjsNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1341
https://bugzilla.redhat.com/show_bug.cgi?id=2459689thin-vec: mozilla/thin-vec: Memory corruption vulnerability via Double-Free/Use-After-Free

EPSS

Процентиль: 7%
0.00168
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 5.1
ubuntu
3 месяца назад

Double-Free / Use-After-Free (UAF) in the `IntoIter::drop` and `ThinVec::clear` functions in the thin_vec crate. A panic in `ptr::drop_in_place` skips setting the length to zero.

CVSS3: 5.1
nvd
3 месяца назад

Double-Free / Use-After-Free (UAF) in the `IntoIter::drop` and `ThinVec::clear` functions in the thin_vec crate. A panic in `ptr::drop_in_place` skips setting the length to zero.

CVSS3: 5.1
debian
3 месяца назад

Double-Free / Use-After-Free (UAF) in the `IntoIter::drop` and `ThinVe ...

CVSS3: 7.3
github
4 месяца назад

thin-vec: Use-After-Free and Double Free in IntoIter::drop When Element Drop Panics

EPSS

Процентиль: 7%
0.00168
Низкий

7.3 High

CVSS3