VDB
Sign up
—

RUSTSEC-2020-0039

`index()` allows out-of-bound read and `remove()` has off-by-one error

Details

`Slab::index()` does not perform the boundary checking, which leads to out-of-bound read access. `Slab::remove()` copies an element from an invalid address due to off-by-one error, resulting in memory leakage and uninitialized memory drop.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/simple-slab
Introduced in: 0.0.0-0Fixed in: 0.3.3

Upgrade simple-slab to 0.3.3 or newer (ecosystem crates.io).

References