VDB
KO

RUSTSEC-2026-0252

Panic-safety unsoundness in `SplitVec::extend_from_slice` (uninitialized read)

Details

`SplitVec::extend_from_slice` increments the logical length `self.len` before cloning the incoming elements into the reserved slots. If an element's `Clone` panics mid-fill, unwinding leaves `self.len` counting slots that were never initialized. A later safe read (`get`, indexing, `iter`) then reads one of those uninitialized slots.

This is reachable from safe Rust — a read of uninitialized memory (CWE-908). It is not a double-free: `SplitVec` has no manual `Drop` and its elements live in a standard `Vec`, so the defect is a read, not a free.

## Impact

A safe read after the panic returns a value built from uninitialized bytes. For a heap-owning element type such as `String`, the resulting value has garbage length/pointer fields.

Confirmed under Miri. AddressSanitizer stays silent for this class, since the uninitialized bytes are consumed as a non-dereferenced field rather than an invalid load or free.

## Fix

Fixed in `orx-split-vec` 4.0.0, which no longer commits the length before the elements are cloned.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io / orx-split-vec
Introduced in: 0.0.0-0 Fixed in: 4.0.0

Upgrade orx-split-vec to 4.0.0 or newer (ecosystem crates.io).

References