VDB
Sign up
—

RUSTSEC-2023-0087

`MaybeUninit` misuse in `simd-json-derive`

Details

An invalid use of `MaybeUninit::uninit().assume_init()` in `simd-json-derive`'s derive macro can cause undefined behavior. The original code used `MaybeUninit` to avoid initialisation of the struct and then set the fields using `ptr::write`. The undefined behavior triggered by this misuse of `MaybeUninit` can lead to invlaid memory access and panics in binaries compiled in release mode (aka simd-json-derive prior to version 0.12 has UB and optimizes into some nonsense)

The `0.12.0` removes this section of code, avoiding the use of MaybeUninit alltogether.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/simd-json-derive
Introduced in: 0.0.0-0Fixed in: 0.12.0

Upgrade simd-json-derive to 0.12.0 or newer (ecosystem crates.io).

References