Skip to content

Potential use-after-free #249

Description

@dmulder

I was just running some AI vetting checks against lru, and it flagged an issue in the update from 0.18.3 -> 0.18.4:

Potential dangling map pointer / memory unsafety — src/lib.rs:1577-1596

The predicate receives &K, which can safely mutate hash-relevant state through Cell, atomics, locks, etc. If the predicate returns false after such mutation, self.map.remove(&key_ref) at line 1587 may fail—or remove an unexpected equal entry—but its result is ignored. The node is then detached and freed, potentially leaving the hash map holding pointers to freed memory. Subsequent safe cache operations could trigger use-after-free and undefined behavior.

I haven't verified this report.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions