—
RUSTSEC-2024-0347
Incorrect usage of `#[repr(packed)]`
Details
The affected versions make unsafe memory accesses under the assumption that `#[repr(packed)]` has a guaranteed field order.
The Rust specification does not guarantee this, and https://github.com/rust-lang/rust/pull/125360 (1.80.0-beta) starts reordering fields of `#[repr(packed)]` structs, leading to illegal memory accesses.
The patched versions `0.9.7` and `0.10.4` use `#[repr(C, packed)]`, which guarantees field order.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/zerovec
Introduced in:
0.0.0-0Fixed in: 0.9.7Upgrade zerovec to 0.9.7 or newer (ecosystem crates.io).