RUSTSEC-2025-0167
`Bitmap::try_from(&[u8])` can create invalid values
Details
The `TryFrom<&[u8]>` implementation for `Bitmap<SIZE>` copies the input bytes into an uninitialized backing store and calls `assume_init()` without validating that the bytes form a valid value of the backing store type. For `SIZE = 1` the backing store is a `bool`, so any input byte other than `0x00` or `0x01` produces an invalid value, which is immediate undefined behavior.
The `AsMut<[u8]>` implementation has the same problem, as it allows safe code to write invalid bit patterns into the backing store through the returned slice.
No fixed version is available, as the crate is unmaintained; its GitHub repository was archived by the owner on 2026-05-03.
Are you affected?
Enter the version of the package you're using.
Affected packages
3.2.0 No fixed version published yet for bitmaps. Pin to a known-safe version or switch to an alternative.
References
- https://crates.io/crates/bitmaps [PACKAGE]
- https://rustsec.org/advisories/RUSTSEC-2025-0167.html [ADVISORY]
- https://github.com/bodil/bitmaps/issues/35 [REPORT]