- Reported
-
- Issued
-
- Package
-
arr
(crates.io)
- Type
-
Vulnerability
- Categories
-
- Aliases
-
- References
-
- Patched
-
no patched versions
Description
arr
crate contains multiple security issues. Specifically,
- It incorrectly implements Sync/Send bounds, which allows to smuggle non-Sync/Send types across the thread boundary.
Index
and IndexMut
implementation does not check the array bound.
Array::new_from_template()
drops uninitialized memory.
Advisory available under CC0-1.0
license.