GHSA-wwxp-hxh6-8gf8
Dashboard / Vulnerabilities / GHSA-wwxp-hxh6-8gf8
Summary: binary_vec_io access memory out-of-bounds in binary_read_to_ref and binary_write_from_ref
Details: Safe functions accept a single `&T` or `&mut T` but multiply by `n` to create slices extending beyond allocated memory when `n > 1`. These functions use `from_raw_parts` to create slices larger than the underlying allocation, violating memory safety. The binary_vec_io repository is archived and unmaintained.
References: https://github.com/RustSec/advisory-db/pull/2428, https://gist.github.com/lewismosciski/57ac3b8b7a861abdd0d7ae6f39de5a9d, https://github.com/10XGenomics/rust-toolbox, https://rustsec.org/advisories/RUSTSEC-2025-0109.html
Affected packages
Package
Name: binary_vec_io
Purl: pkg:cargo/binary_vec_io
Affected ranges
Type: SEMVER
Events:
