CRITICAL9.8
GHSA-36xw-hgfv-jwm7
Multiple security issues including data race, buffer overflow, and uninitialized memory drop in arr
Details
arr crate contains multiple security issues. Specifically,
1. It incorrectly implements Sync/Send bounds, which allows to smuggle non-Sync/Send types across the thread boundary. 2. Index and IndexMut implementation does not check the array bound. 3. Array::new_from_template() drops uninitialized memory.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/arr
Introduced in:
0No fixed version published yet for arr. Pin to a known-safe version or switch to an alternative.