RUSTSEC-2025-0107
Dashboard / Vulnerabilities / RUSTSEC-2025-0107
Summary: Uninitialized memory exposure in any_as_u8_slice
Details: The safe function `any_as_u8_slice` can create byte slices that reference uninitialized memory when used with types containing padding bytes. The function uses `slice::from_raw_parts` to create a `&[u8]` covering the entire size of a type, including padding bytes. According to Rust's documentation, `from_raw_parts` requires all bytes to be properly initialized, but padding bytes in structs are not guaranteed to be initialized. This violates the safety contract and causes undefined behavior.
References: https://crates.io/crates/borrowck_sacrifices, https://rustsec.org/advisories/RUSTSEC-2025-0107.html, https://github.com/alexpyattaev/borrowck_sacrifices/issues/1
Affected packages
Package
Name: borrowck_sacrifices
Purl: pkg:cargo/borrowck_sacrifices
Affected ranges
Type: SEMVER
Events:
