VDB
Sign up
—

RUSTSEC-2026-0123

Out-of-bounds read in `bytes_helper` public safe functions

Details

The `bytes_helper` module contains multiple public functions (`into_arr4()`, `into_arr2()`, `u8_from_le_bytes()`) that use `slice.get_unchecked(pos..pos + N)` without verifying that `pos + N <= slice.len()`. These are public safe API functions, allowing any caller to trigger undefined behavior by passing invalid positions.

For example, calling `into_arr4(&data, 10)` where `data` is a 3-byte slice causes an out-of-bounds access since position 10 exceeds the slice length.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/rustdx
Introduced in: 0.0.0-0Fixed in: 0.4.4

Upgrade rustdx to 0.4.4 or newer (ecosystem crates.io).

References