RUSTSEC-2024-0448

Source
https://rustsec.org/advisories/RUSTSEC-2024-0448
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2024-0448.json
JSON Data
https://api.osv.dev/v1/vulns/RUSTSEC-2024-0448
Published
2024-11-25T12:00:00Z
Modified
2026-10-03T08:15:02Z
Summary
`parse_arguments` reads a caller-supplied pointer as a slice
Details

parse_arguments is safe. It takes arguments: *const AnyObject and argc, and calls slice::from_raw_parts(arguments, argc as usize).

It does not check that arguments is non-null and aligned, or that argc elements are initialized. Safe Rust can pass a null pointer or a length past the allocation. The maintainer confirmed this on 2026-10-03, including a debug abort on Rust 1.78+ when Ruby calls an arity -1 method (to_s via format, puts, or Array#join) with a NULL argv and argc of 0.

Database specific
{
    "license":  "CC0-1.0"
}
References

Affected packages

crates.io / rutie

Package

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0-0
Fixed
0.10.3
Introduced
0.11.0
Fixed
0.11.3
Introduced
0.12.0
Fixed
0.12.1
Introduced
0.13.0
Fixed
0.13.1
Introduced
0.14.0
Fixed
0.14.1

Ecosystem specific

{
    "affected_functions":  null,
    "affects":  {
        "arch":  [],
        "functions":  [],
        "os":  []
    }
}

Database specific

categories
[
    "memory-corruption"
]
cvss
null
informational
"unsound"
source
"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2024-0448.json"