{"id":"RUSTSEC-2023-0126","title":"Aliasing violation in `OrdSet` insertion","summary":"Aliasing violation in `OrdSet` insertion","severity":"none","vendor":"im","product":"im","ecosystem":"rust","affected":["im >= 0.0.0-0"],"published":"2023-02-04","updated":"2026-08-10","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/RUSTSEC-2023-0126","references":[{"url":"https://crates.io/crates/im"},{"url":"https://rustsec.org/advisories/RUSTSEC-2023-0126.html"},{"url":"https://github.com/bodil/im-rs/issues/207"}],"tags":["osv","rust"],"ingestedAt":"2026-08-11T19:17:10.156Z","slug":"RUSTSEC-2023-0126","body":"## Overview\n\nInserting into an `im::OrdSet` (for example by collecting an iterator into one) can violate\nRust's aliasing rules: Miri reports a stacked borrows violation in\n`sized_chunks::Chunk::force_copy()`, which is called during insertion, where a shared borrow\nis invalidated by a unique borrow before the read through it completes.\nThis is undefined behavior, reachable from safe code.\n\nNo fixed version is available, as the crate is unmaintained; its GitHub\nrepository was archived by the owner on 2026-05-03.\n\n## Affected packages\n\n- `im >= 0.0.0-0`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}