VDB
Sign up
—

RUSTSEC-2026-0309

`SinglyLinkedList::remove` dereferences a null link

Details

In versions before 0.2.1, `SinglyLinkedList::remove` is safe and walks the intrusive list with an unchecked dereference. On an empty list, or when `node` is not in the list, `(*current_elm).next` reads a null pointer. That is undefined behavior. The list head is a raw `*mut Node<T>`, and safe code can construct the empty list.

The maintainer fixed this in 0.2.1 by rejecting those two cases with an unconditional `assert!` before the pointer is followed, matching the upstream Zig `unwrap` on the same paths. 0.2.0 was yanked. Versions 0.1.0 through 0.1.13 are still published and still contain the unchecked walk.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/bun_collections
Introduced in: 0.0.0-0Fixed in: 0.2.1

Upgrade bun_collections to 0.2.1 or newer (ecosystem crates.io).

References