VDB
EN

RUSTSEC-2026-0220

Uint shift operations: incorrect overflow flags and truncated shift amounts

상세

`Uint::overflowing_shl`/`overflowing_shr` returned false-negative overflow flags. `overflowing_shl` missed bits shifted above `BITS` but within the top limb (non-limb-aligned widths such as `U160`), and limbs wholly discarded by shifts >= 64; `overflowing_shr` missed wholly discarded low limbs. Shifted values were correct; only the flag was wrong.

The wrong flag propagates: `checked_shl`/`checked_shr` return `Some` instead of `None`, `strict_*` fail to panic, and `saturating_*` return a wrapped value instead of saturating. The incorrect `checked_shl` result causes `to_base_be` (and string formatting) to loop forever on no-alloc builds for non-limb-aligned widths — a denial of service if formatting is reachable from untrusted input.

Separately, `wrapping_shl`/`wrapping_shr` on 64/128/256-bit types truncated the shift amount modulo 2^32, so shifts >= 2^32 returned an incorrectly wrapped value instead of zero; on 32-bit targets the generic path also truncated 64-bit shift amounts.

Callers using checked or saturating shift semantics on untrusted shift amounts may compute incorrect results.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

crates.io / ruint
최초 영향 버전: 0.0.0-0 수정 버전: 1.20.0

Upgrade ruint to 1.20.0 or newer (ecosystem crates.io).

참고