—
RUSTSEC-2026-0133
Invalid pointer arithmetic in `iter()` and `iter_mut()`
Details
The `iter()` and `iter_mut()` APIs compute `current = (&children[0] as *const *const RawAutoChild).sub(1)`, which performs pointer subtraction going before the start of the allocation. This is undefined behavior per Rust's pointer arithmetic rules.
This can be triggered through safe public APIs — `iter()` and `iter_mut()` — with no `unsafe` required from the caller.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/auto_vec
Introduced in:
0.0.0-0No fixed version published yet for auto_vec. Pin to a known-safe version or switch to an alternative.