VDB
Sign up
LOW

GHSA-2326-pfpj-vx3h

lexical-core has multiple soundness issues

Details

`RUSTSEC-2024-0377` contains multiple soundness issues:

1. [Bytes::read() allows creating instances of types with invalid bit patterns](https://github.com/Alexhuszagh/rust-lexical/issues/102) 1. [BytesIter::read() advances iterators out of bounds](https://github.com/Alexhuszagh/rust-lexical/issues/101) 1. [The `BytesIter` trait has safety invariants but is public and not marked `unsafe`](https://github.com/Alexhuszagh/rust-lexical/issues/104) 1. [`write_float()` calls `MaybeUninit::assume_init()` on uninitialized data, which is is not allowed by the Rust abstract machine](https://github.com/Alexhuszagh/rust-lexical/issues/95) 1. [`radix()` calls `MaybeUninit::assume_init()` on uninitialized data, which is is not allowed by the Rust abstract machine](https://github.com/Alexhuszagh/rust-lexical/issues/126)

Version 1.0 fixes these issues, removes the vast majority of `unsafe` code, and also fixes some correctness issues.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/lexical-core
Introduced in: 0Fixed in: 1.0.0

Upgrade lexical-core to 1.0.0 or newer (ecosystem crates.io).

References