—
RUSTSEC-2025-0106
Undefined behavior in index_of_ptr with empty slices
Details
The safe function `index_of_ptr` causes undefined behavior when called with an empty slice.
The issue occurs in the line `ptr.add(slice.len() - 1)` which underflows when `slice.len()` is 0, creating a pointer with a massive offset. According to Rust's safety rules, creating such a pointer causes immediate undefined behavior.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/orx-pinned-vec
Introduced in:
0.0.0-0Fixed in: 3.21.0Upgrade orx-pinned-vec to 3.21.0 or newer (ecosystem crates.io).