Junglewise Threat Intelligence

owned-alloc double free in drop_in_place when Drop panics

Severity: info · Published 2026-09-09

Vendors: crates.io.

Executive brief

owned-alloc is a Rust library for managing memory allocations. When a value stored in OwnedAlloc or MaybeUninitAlloc has a destructor that panics, the library fails to properly clean up, leading to double-free and use-after-free memory corruption. This can cause memory safety violations and potentially lead to denial of service or arbitrary code execution in applications that use this crate with panic-prone destructors.

Technical details

The vulnerability exists in OwnedAlloc::drop_in_place and MaybeUninitAlloc::drop_in_place, which manually destroy a contained value and then call mem::forget to transfer ownership. If the user-provided Drop implementation panics, the mem::forget is skipped, causing the OwnedAlloc destructor to run during unwinding and drop the same value a second time, resulting in double-free (CWE-415) and use-after-free (CWE-416) on heap-allocated data. No unsafe code is required from the caller; storing any value whose Drop can panic is sufficient to trigger the vulnerability. The crate has not been maintained since 2018 and no fixed version exists.

Affected products

  • owned-alloc crate authors owned-alloc <=0.2.0

Timeline

  • 2026-09-09: disclosed
  • 2026-09-21: advisory

References

Related threats