—
RUSTSEC-2023-0087
`MaybeUninit` misuse in `simd-json-derive`
Details
An invalid use of `MaybeUninit::uninit().assume_init()` in `simd-json-derive`'s derive macro can cause undefined behavior. The original code used `MaybeUninit` to avoid initialisation of the struct and then set the fields using `ptr::write`. The undefined behavior triggered by this misuse of `MaybeUninit` can lead to invlaid memory access and panics in binaries compiled in release mode (aka simd-json-derive prior to version 0.12 has UB and optimizes into some nonsense)
The `0.12.0` removes this section of code, avoiding the use of MaybeUninit alltogether.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/simd-json-derive
Introduced in:
0.0.0-0Fixed in: 0.12.0Upgrade simd-json-derive to 0.12.0 or newer (ecosystem crates.io).