VDB
Sign up
HIGH7.5

GHSA-q948-x8rf-888m

os_str_bytes relies on undefined behavior of `char::from_u32_unchecked`

Details

The Windows implementation of this crate relied on the behavior of std::char::from_u32_unchecked when its safety clause is violated. Even though this worked with Rust versions up to 1.42 (at least), that behavior could change with any new Rust version, possibly leading a security issue.

The flaw was corrected in version 2.0.0.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/os_str_bytes
Introduced in: 0Fixed in: 2.0.0

Upgrade os_str_bytes to 2.0.0 or newer (ecosystem crates.io).

References