RUSTSEC-2025-0054
ArrayQueue::push_front is not panic-safe
Details
The safe API `array_queue::ArrayQueue::push_front` can lead to deallocating uninitialized memory if a panic occurs while invoking the `clone` method on the passed argument.
Specifically, `push_front` receives an argument that is intended to be cloned and pushed, whose type implements the `Clone` trait. Furthermore, the method updates the queue's `start` index before initializing the slot for the newly pushed element. User-defined implementations of `Clone` may include a `clone` method that can panic. If such a panic occurs during initialization, the structure is left with an advanced `start` index pointing to an uninitialized slot. When `ArrayQueue` is later dropped, its destructor treats that slot as initialized and attempts to drop it, resulting in an attempt to free uninitialized memory.
The bug was fixed in commit `728fe1b`.
Are you affected?
Enter the version of the package you're using.
Affected packages
0.3.0Fixed in: 0.4.0Upgrade array-queue to 0.4.0 or newer (ecosystem crates.io).