RUSTSEC-2021-0046

Source
https://rustsec.org/advisories/RUSTSEC-2021-0046
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2021-0046.json
JSON Data
https://api.osv.dev/v1/vulns/RUSTSEC-2021-0046
Aliases
Withdrawn
2026-08-29T12:00:00Z
Published
2021-02-17T12:00:00Z
Modified
2026-08-29T12:00:00Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
misc::vec_with_size() can drop uninitialized memory if clone panics
Details

misc::vec_with_size creates a vector of the provided size and immediately calls vec.set_len(size) on it, initially filling it with uninitialized memory. It then inserts elements using vec[i] = value.clone().

If the value.clone() call panics, uninitialized items in the vector will be dropped leading to undefined behavior.

Withdrawal

This advisory has been withdrawn because the above unsoundness cannot be triggered in safe code by dependents of the crate, as the Clone generic of private function misc::vec_with_size only instantiates to primitive types in public functions, which is impossible to panic.

Database specific
{
    "license": "CC0-1.0"
}
References

Affected packages

crates.io / telemetry

Package

Name
telemetry
View open source insights on deps.dev
Purl
pkg:cargo/telemetry

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0-0

Ecosystem specific

{
    "affected_functions": null,
    "affects": {
        "arch": [],
        "functions": [],
        "os": []
    }
}

Database specific

categories
[
    "memory-corruption"
]
cvss
"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
informational
null
source
"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2021-0046.json"