Double-Free / Use-After-Free (UAF) in the `IntoIter::drop` and `ThinVec::clear` functions in the thin_vec crate. A panic in `ptr::drop_in_place` skips setting the length to zero.
References
Configurations
History
No history.
Information
Published : 2026-04-20 11:16
Updated : 2026-07-15 01:16
NVD link : CVE-2026-6654
Mitre link : CVE-2026-6654
CVE.ORG link : CVE-2026-6654
JSON object : View
Products Affected
mozilla
- thin-vec
