{"id":"RUSTSEC-2025-0171","title":"soundness issue","summary":"soundness issue","severity":"none","vendor":"mod3d-base","product":"mod3d-base","ecosystem":"rust","affected":["mod3d-base >= 0.0.0-0, < 0.3.0"],"patched":["mod3d-base 0.3.0"],"published":"2025-05-06","updated":"2026-08-31","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/RUSTSEC-2025-0171","references":[{"url":"https://crates.io/crates/mod3d-base"},{"url":"https://rustsec.org/advisories/RUSTSEC-2025-0171.html"},{"url":"https://github.com/atthecodeface/model3d"}],"tags":["osv","rust"],"ingestedAt":"2026-08-31T19:30:40.095Z","slug":"RUSTSEC-2025-0171","body":"## Overview\n\n`mod3d_base::BufferData::as_ptr` lack of sufficient checks to its public self field `byte_offset` and used unsafely to do the pointer calculation.\n\n## Affected packages\n\n- `mod3d-base >= 0.0.0-0, < 0.3.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `mod3d-base 0.3.0`","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}