VDB
Sign up
—

RUSTSEC-2018-0018

smallvec creates uninitialized value of any type

Details

Affected versions of this crate called `mem::uninitialized()` to create values of a user-supplied type `T`. This is unsound e.g. if `T` is a reference type (which must be non-null and thus may not remain uninitialized). The flaw was corrected by avoiding the use of `mem::uninitialized()`, using `MaybeUninit` instead.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/smallvec
Introduced in: 0.0.0-0Fixed in: 0.6.13

Upgrade smallvec to 0.6.13 or newer (ecosystem crates.io).

References