—
RUSTSEC-2026-0002
`IterMut` violates Stacked Borrows by invalidating internal pointer
Details
Affected versions of this crate contain a soundness issue in the `IterMut` iterator implementation. The `IterMut::next` and `IterMut::next_back` methods temporarily create an exclusive reference to the key when dereferencing the internal node pointer.
This invalidates the shared pointer held by the internal `HashMap`, violating Stacked Borrows rules.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/lru
Introduced in:
0.9.0Fixed in: 0.16.3Upgrade lru to 0.16.3 or newer (ecosystem crates.io).