PT-2026-80709 · Crates.Io · Orx-Split-Vec
Publicado
2026-08-11
·
Atualizado
2026-08-11
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
SplitVec::extend from slice increments the logical length self.len before cloning the incoming elements into the reserved slots. If an element's Clone panics mid-fill, unwinding leaves self.len counting slots that were never initialized. A later safe read (get, indexing, iter) then reads one of those uninitialized slots.This is reachable from safe Rust — a read of uninitialized memory (CWE-908). It is not a double-free:
SplitVec has no manual Drop and its elements live in a standard Vec, so the defect is a read, not a free.Impact
A safe read after the panic returns a value built from uninitialized bytes. For a heap-owning element type such as
String, the resulting value has garbage length/pointer fields.Confirmed under Miri. AddressSanitizer stays silent for this class, since the uninitialized bytes are consumed as a non-dereferenced field rather than an invalid load or free.
Fix
Fixed in
orx-split-vec 4.0.0, which no longer commits the length before the elements are cloned. Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Orx-Split-Vec