GHSA-2326-pfpj-vx3h
lexical-core has multiple soundness issues
Details
`RUSTSEC-2024-0377` contains multiple soundness issues:
1. [Bytes::read() allows creating instances of types with invalid bit patterns](https://github.com/Alexhuszagh/rust-lexical/issues/102) 1. [BytesIter::read() advances iterators out of bounds](https://github.com/Alexhuszagh/rust-lexical/issues/101) 1. [The `BytesIter` trait has safety invariants but is public and not marked `unsafe`](https://github.com/Alexhuszagh/rust-lexical/issues/104) 1. [`write_float()` calls `MaybeUninit::assume_init()` on uninitialized data, which is is not allowed by the Rust abstract machine](https://github.com/Alexhuszagh/rust-lexical/issues/95) 1. [`radix()` calls `MaybeUninit::assume_init()` on uninitialized data, which is is not allowed by the Rust abstract machine](https://github.com/Alexhuszagh/rust-lexical/issues/126)
Version 1.0 fixes these issues, removes the vast majority of `unsafe` code, and also fixes some correctness issues.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 1.0.0Upgrade lexical-core to 1.0.0 or newer (ecosystem crates.io).
References
- https://github.com/Alexhuszagh/rust-lexical/issues/101[WEB]
- https://github.com/Alexhuszagh/rust-lexical/issues/102[WEB]
- https://github.com/Alexhuszagh/rust-lexical/issues/104[WEB]
- https://github.com/Alexhuszagh/rust-lexical/issues/126[WEB]
- https://github.com/Alexhuszagh/rust-lexical/issues/95[WEB]
- https://github.com/Alexhuszagh/rust-lexical[PACKAGE]
- https://github.com/advisories/GHSA-c2hm-mjxv-89r4[ADVISORY]
- https://rustsec.org/advisories/RUSTSEC-2023-0055[WEB]
- https://rustsec.org/advisories/RUSTSEC-2023-0086.html[WEB]