VDB
Sign up
—

RUSTSEC-2026-0001

Potential Undefined Behaviors in `Arc<T>`/`Rc<T>` impls of `from_value` on OOM

Details

The `SharedPointer::alloc` implementation for `sync::Arc<T>` and `rc::Rc<T>` in `rkyv/src/impls/alloc/rc/atomic.rs` (and `rc.rs`) does not check if the allocator returns a null pointer on OOM (Out of Memory).

This null pointer can flow through to `SharedPointer::from_value`, which calls `Box::from_raw(ptr)` with the null pointer. This triggers undefined behavior when utilizing safe deserialization APIs (such as `rkyv::from_bytes` or `rkyv::deserialize_using`) if an OOM condition occurs during the allocation of the shared pointer.

The issue is reachable through safe code and violates Rust's safety guarantees.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/rkyv
Introduced in: 0.0.0-0Fixed in: 0.7.46

Upgrade rkyv to 0.7.46 or newer (ecosystem crates.io).

References