getsentry / getsentry/sentry-cli

RUSTSEC-2026-0253: Potential use-after-free due to lack of panic safety in `LruCache::pop()`

Open
#3,394 1 comment 0 reactions 0 assignees View on GitHub
rust
Dominant language
Rust
Stars
1k
Forks
255
Avg merge
5d 13h
Merged PRs (30d)
8

Description

> Potential use-after-free due to lack of panic safety in `LruCache::pop()`

| Details | |
| ------------------- | ---------------------------------------------- |
| Status | unsound |
| Package | `lru` |
| Version | `0.16.4` |
| URL | [https://github.com/jeromefroe/lru-rs/pull/238](https://github.com/jeromefroe/lru-rs/pull/238) |
| Date | 2026-05-12 |

`LruCache::pop()` in `lru` was not panic-safe. If the `Drop` implementation of a stored key panics during `pop()`, `self.detach()` is never called, leaving dangling pointers in the internal doubly-linked list.

A subsequent cache operation that triggers eviction can then dereference these dangling pointers:
- The node is freed from the map, but remains linked in the LRU list due to the skipped `detach()` call
- When a new insertion causes eviction, the LRU traversal encounters the dangling pointer
- This results in a write to already-freed memory during the eviction process

## Impact

- **CWE-416 (Use-After-Free):** memory corruption when subsequent cache operations access freed node pointers in the linked list
- **CWE-415 (Double Free):** potential heap corruption when the same memory is freed multiple times

Both types of undefined behavior can be invoked in safe Rust, but only if unwinding panics are enabled and `std::panic::catch_unwind` is used with key types that have potentially-panicking `Drop` implementations.

## Fix

Fixed in `lru` 0.18.2 by detaching the node from the linked list before freeing it and dropping the key ([lru-rs#238](https://github.com/jeromefroe/lru-rs/pull/238)).

See [advisory page](https://rustsec.org/advisories/RUSTSEC-2026-0253.html) for additional details.

Contributor guide

Open the contributing guide

Research direction

Start by tracing how sentry-cli depends on the lru package and identify the dependency manifest or lockfile that selects version 0.16.4. Update the resolved dependency to the fixed 0.18.2 release, then run the repository's available checks to confirm dependency resolution and existing behavior remain intact.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
58/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.