VDB
KO

RUSTSEC-2025-0167

`Bitmap::try_from(&[u8])` can create invalid values

Details

The `TryFrom<&[u8]>` implementation for `Bitmap<SIZE>` copies the input bytes into an uninitialized backing store and calls `assume_init()` without validating that the bytes form a valid value of the backing store type. For `SIZE = 1` the backing store is a `bool`, so any input byte other than `0x00` or `0x01` produces an invalid value, which is immediate undefined behavior.

The `AsMut<[u8]>` implementation has the same problem, as it allows safe code to write invalid bit patterns into the backing store through the returned slice.

No fixed version is available, as the crate is unmaintained; its GitHub repository was archived by the owner on 2026-05-03.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io / bitmaps
Introduced in: 3.2.0

No fixed version published yet for bitmaps. Pin to a known-safe version or switch to an alternative.

References