RUSTSEC-2026-0309
`SinglyLinkedList::remove` dereferences a null link
Details
In versions before 0.2.1, `SinglyLinkedList::remove` is safe and walks the intrusive list with an unchecked dereference. On an empty list, or when `node` is not in the list, `(*current_elm).next` reads a null pointer. That is undefined behavior. The list head is a raw `*mut Node<T>`, and safe code can construct the empty list.
The maintainer fixed this in 0.2.1 by rejecting those two cases with an unconditional `assert!` before the pointer is followed, matching the upstream Zig `unwrap` on the same paths. 0.2.0 was yanked. Versions 0.1.0 through 0.1.13 are still published and still contain the unchecked walk.
Are you affected?
Enter the version of the package you're using.
Affected packages
0.0.0-0Fixed in: 0.2.1Upgrade bun_collections to 0.2.1 or newer (ecosystem crates.io).