VDB
Sign up
—

RUSTSEC-2025-0137

Unsoundness of safe `reciprocal_mg10`

Details

The function `reciprocal_mg10` is marked as safe but can trigger undefined behavior (out-of-bounds access) because it relies on `debug_assert!` for safety checks instead of `assert!`.

When compiled in release mode, the `debug_assert!` is optimized out, potentially allowing invalid inputs to cause memory corruption.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/ruint
Introduced in: 0.0.0-0Fixed in: 1.17.1

Upgrade ruint to 1.17.1 or newer (ecosystem crates.io).

References