Vulnerability RUSTSEC-2024-0448
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
1 year ago
November 25, 2024 at 12:00 PM UTC
`parse_arguments` reads a caller-supplied pointer as a slice
0.0.1 - 0.5.6 and 0.6.0 - 0.10.2
0.0.1 - 0.5.6 and 0.6.0 - 0.10.2
Summary
`parse_arguments` reads a caller-supplied pointer as a slice
Details
parse_arguments is safe. It takes arguments: *const AnyObject and argc, and calls slice::from_raw_parts(arguments, argc as usize).
It does not check that arguments is non-null and aligned, or that argc elements are initialized. Safe Rust can pass a null pointer or a length past the allocation. The maintainer confirmed this on 2026-10-03, including a debug abort on Rust 1.78+ when Ruby calls an arity -1 method (to_s via format, puts, or Array#join) with a NULL argv and argc of 0.
Impacted packages
Timeline
Published
1 year ago
November 25, 2024 at 12:00 PM UTC
Fixed (0.10.3)
11 hours ago
October 03, 2026 at 12:31 AM UTC
Fixed (0.11.3)
11 hours ago
October 03, 2026 at 12:35 AM UTC
Fixed (0.12.1)
11 hours ago
October 03, 2026 at 12:40 AM UTC
Fixed (0.13.1)
11 hours ago
October 03, 2026 at 12:46 AM UTC
Fixed (0.14.1)
11 hours ago
October 03, 2026 at 12:56 AM UTC
Last Modified
4 hours ago
October 03, 2026 at 08:15 AM UTC