Executive brief
The unicycle Rust library manages concurrent futures in a container. A use-after-free memory safety bug occurs if a future's cleanup function panics while the container is being dropped, potentially leading to memory corruption or crashes. This vulnerability is triggered automatically when the container is destroyed and requires no special method calls.
Technical details
The vulnerability is a use-after-free (CWE-416) in the Storage::clear method. When iterating over the task slab and dropping futures, if a future's Drop implementation panics, the length is never committed via set_len(0), leaving stale pointers in the slab. The Storage::drop implementation then calls clear again, dereferencing already-freed allocations. This is reachable from safe Rust through the Unordered container's drop implementation.
Affected products
- unicycle unicycle before 0.10.3
Timeline
- 2026-09-12: disclosed
- 2026-09-22: patched: Version 0.10.3 released