VDB
Sign up
CRITICAL9.8

GHSA-36xw-hgfv-jwm7

Multiple security issues including data race, buffer overflow, and uninitialized memory drop in arr

Details

arr crate contains multiple security issues. Specifically,

1. It incorrectly implements Sync/Send bounds, which allows to smuggle non-Sync/Send types across the thread boundary. 2. Index and IndexMut implementation does not check the array bound. 3. Array::new_from_template() drops uninitialized memory.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/arr
Introduced in: 0

No fixed version published yet for arr. Pin to a known-safe version or switch to an alternative.

References