PT-2025-62912 · Crates.Io · Bitmaps
Published
2025-12-25
·
Updated
2025-12-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
The
TryFrom<&[u8]> implementation for Bitmap<SIZE> copies the input bytes
into an uninitialized backing store and calls assume init() without
validating that the bytes form a valid value of the backing store type. For
SIZE = 1 the backing store is a bool, so any input byte other than 0x00
or 0x01 produces an invalid value, which is immediate undefined behavior.The
AsMut<[u8]> implementation has the same problem, as it allows safe code
to write invalid bit patterns into the backing store through the returned slice.No fixed version is available, as the crate is unmaintained; its GitHub
repository was archived by the owner on 2026-05-03.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bitmaps