PT-2025-62915 · Crates.Io · Hugepage-Rs
Published
2025-04-24
·
Updated
2025-04-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
hugepage rs::dealloc was a publicly accessible safe function. It accepted an arbitrary raw pointer and Layout, then forwarded them to the hugepage allocator's GlobalAlloc::dealloc implementation.GlobalAlloc::dealloc requires callers to ensure that the pointer denotes a block of memory currently allocated by the allocator and that the layout is the same layout used for the allocation. The safe wrapper neither verified these requirements nor marked them as
unsafe preconditions for callers.Affected versions therefore allowed safe Rust code to call
dealloc with an invalid pointer, a pointer not allocated by the hugepage allocator, or an incorrect layout, which could cause undefined behavior.The upstream repository fixed this in version
0.1.1 by marking dealloc as unsafe and documenting the caller's safety requirements. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hugepage-Rs