VDB
Sign up
—

RUSTSEC-2025-0107

Uninitialized memory exposure in any_as_u8_slice

Details

The safe function `any_as_u8_slice` can create byte slices that reference uninitialized memory when used with types containing padding bytes.

The function uses `slice::from_raw_parts` to create a `&[u8]` covering the entire size of a type, including padding bytes. According to Rust's documentation, `from_raw_parts` requires all bytes to be properly initialized, but padding bytes in structs are not guaranteed to be initialized. This violates the safety contract and causes undefined behavior.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/borrowck_sacrifices
Introduced in: 0.0.0-0Fixed in: 0.2.0

Upgrade borrowck_sacrifices to 0.2.0 or newer (ecosystem crates.io).

References