RUSTSEC-2026-0001
Potential Undefined Behaviors in `Arc<T>`/`Rc<T>` impls of `from_value` on OOM
Details
The `SharedPointer::alloc` implementation for `sync::Arc<T>` and `rc::Rc<T>` in `rkyv/src/impls/alloc/rc/atomic.rs` (and `rc.rs`) does not check if the allocator returns a null pointer on OOM (Out of Memory).
This null pointer can flow through to `SharedPointer::from_value`, which calls `Box::from_raw(ptr)` with the null pointer. This triggers undefined behavior when utilizing safe deserialization APIs (such as `rkyv::from_bytes` or `rkyv::deserialize_using`) if an OOM condition occurs during the allocation of the shared pointer.
The issue is reachable through safe code and violates Rust's safety guarantees.
Are you affected?
Enter the version of the package you're using.
Affected packages
0.0.0-0Fixed in: 0.7.46Upgrade rkyv to 0.7.46 or newer (ecosystem crates.io).