RustSec logo

History ⋅ Edit ⋅ JSON (OSV)

RUSTSEC-2026-0309

SinglyLinkedList::remove dereferences a null link

Reported
Issued
Package
bun_collections (crates.io)
Type
INFO Unsound
Categories
Keywords
#null-pointer
References
Patched
  • >=0.2.1
Affected Functions
Version
bun_collections::pool::SinglyLinkedList::remove
  • <0.2.1

Description

In versions before 0.2.1, SinglyLinkedList::remove is safe and walks the intrusive list with an unchecked dereference. On an empty list, or when node is not in the list, (*current_elm).next reads a null pointer. That is undefined behavior. The list head is a raw *mut Node<T>, and safe code can construct the empty list.

The maintainer fixed this in 0.2.1 by rejecting those two cases with an unconditional assert! before the pointer is followed, matching the upstream Zig unwrap on the same paths. 0.2.0 was yanked. Versions 0.1.0 through 0.1.13 are still published and still contain the unchecked walk.

Advisory available under CC0-1.0 license.