VDB
Sign up
—

RUSTSEC-2025-0047

Out-of-bounds access in `get_disjoint_mut` due to incorrect bounds check

Details

## Impact The `get_disjoint_mut` method in slab v0.4.10 incorrectly checked if indices were within the slab's capacity instead of its length, allowing access to uninitialized memory. This could lead to undefined behavior or potential crashes.

## Patches This has been fixed in slab v0.4.11.

## Workarounds Avoid using `get_disjoint_mut` with indices that might be beyond the slab's actual length, or upgrade to v0.4.11 or later.

## References * [https://github.com/tokio-rs/slab/pull/152](https://github.com/tokio-rs/slab/pull/152)

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/slab
Introduced in: 0.4.10Fixed in: 0.4.11

Upgrade slab to 0.4.11 or newer (ecosystem crates.io).

References