PT-2026-103513 · Crates.Io · Bun Collections
Published
2026-09-20
·
Updated
2026-09-20
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In versions before 0.2.1,
SinglyLinkedList::remove is safe and walks the intrusive list with an unchecked dereference. On an empty list, or when node is not in the list, (*current elm).next reads a null pointer. That is undefined behavior. The list head is a raw *mut Node<T>, and safe code can construct the empty list.The maintainer fixed this in 0.2.1 by rejecting those two cases with an unconditional
assert! before the pointer is followed, matching the upstream Zig unwrap on the same paths. 0.2.0 was yanked. Versions 0.1.0 through 0.1.13 are still published and still contain the unchecked walk. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bun Collections