
CVE-2026-6654 Double-Free / Use-After-Free (UAF) in the `IntoIter::drop` and `ThinVec::clear` functions in the thin_vec crate. A panic in `ptr::drop_in_place` skips setting the lengt… https://www.cve.org/CVERecord?id=CVE-2026-6654
Post summary
The post details a new double‑free/Use‑After‑Free flaw in the Rust `thin_vec` crate, citing affected functions but offering no PoC, exploit code, patch, or evidence of active exploitation.
