Vulnerability RUSTSEC-2026-0309

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
7 days ago
September 20, 2026 at 12:00 PM UTC
`SinglyLinkedList::remove` dereferences a null link
0.1.0 - 0.2.0
0.1.0 - 0.2.0

Summary

`SinglyLinkedList::remove` dereferences a null link

Details

In versions before 0.2.1, SinglyLinkedList::remove is safe and walks the intrusive list with an unchecked dereference. On an empty list, or when node is not in the list, (*current_elm).next reads a null pointer. That is undefined behavior. The list head is a raw *mut Node<T>, and safe code can construct the empty list.

The maintainer fixed this in 0.2.1 by rejecting those two cases with an unconditional assert! before the pointer is followed, matching the upstream Zig unwrap on the same paths. 0.2.0 was yanked. Versions 0.1.0 through 0.1.13 are still published and still contain the unchecked walk.

Impacted packages

Timeline

Published
7 days ago
September 20, 2026 at 12:00 PM UTC
Fixed (0.2.1)
7 days ago
September 20, 2026 at 11:56 AM UTC
Last Modified
2 days ago
September 25, 2026 at 06:00 PM UTC