Skip to content

Add advisory for hecs: double free when a component's Drop panics - #3323

Open
tooson9010-spec wants to merge 1 commit into
rustsec:mainfrom
tooson9010-spec:hecs-double-free-on-drop-panic
Open

tooson9010-spec wants to merge 1 commit into
rustsec:mainfrom
tooson9010-spec:hecs-double-free-on-drop-panic

Conversation

@tooson9010-spec

Copy link
Copy Markdown
Contributor

Affected crate(s)

  • hecs (150,270 recent downloads per crates.io)

Links to upstream issue(s) or PR(s)

Fixed in Ralith/hecs#471 and Ralith/hecs#474, released in 0.11.2.

Severity

Panic-safety unsoundness. Several hecs operations run component destructors before committing the bookkeeping that records which slots hold live components. A panicking component Drop skips that commit, so already-dropped slots are still treated as live and a later Drop for Archetype or a subsequent operation destroys them again — a double free (CWE-415) reachable from safe Rust, confirmed under AddressSanitizer on 0.11.1. Reached from World::clear, World::despawn, World::spawn_at, World::spawn_column_batch_at and CommandBuffer::run_on. Fixed in 0.11.2.

Checklist

  • Advisory filename(s) starts with RUSTSEC-0000-0000 as the ID
  • date field is set to the public disclosure date
  • Contains a concise and descriptive title after advisory metadata
  • Asked maintainer(s) if publishing an advisory is appropriate

@djc

djc commented Oct 8, 2026

Copy link
Copy Markdown
Member

Given this comment from the maintainer:

Sure, if you like. It's difficult to imagine a realistic scenario in which this could be deliberately triggered and present an actual security hazard, so the severity should be recorded accordingly, but it's certainly not technically impossible.

I don't think having an advisory makes sense.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants