RUSTSEC-2025-0105
Dashboard / Vulnerabilities / RUSTSEC-2025-0105
Summary: Uninitialized memory exposure in create_ring_buffer
Details: The safe function `create_ring_buffer` allocates a buffer using `Vec::with_capacity` followed by `set_len`, creating a `Box<[T]>` containing uninitialized memory. This leads to undefined behavior when functions like `write_slices` create typed slices (e.g., `&mut [bool]`) over the uninitialized memory, violating Rust's validity invariants. The issue has been confirmed using Miri. Fixed in version 0.2.2 by using `resize_with` to properly initialize the buffer with `T::default()`, adding a `T: Default` bound to ensure sound initialization.
References: https://crates.io/crates/direct_ring_buffer, https://rustsec.org/advisories/RUSTSEC-2025-0105.html, https://github.com/ain1084/direct_ring_buffer/issues/1, https://github.com/ain1084/direct_ring_buffer/pull/2
Affected packages
Package
Name: direct_ring_buffer
Purl: pkg:cargo/direct_ring_buffer
Affected ranges
Type: SEMVER
Events:
