{"id":"RUSTSEC-2026-0309","title":"`SinglyLinkedList::remove` dereferences a null link","summary":"`SinglyLinkedList::remove` dereferences a null link","severity":"none","vendor":"bun_collections","product":"bun_collections","ecosystem":"rust","affected":["bun_collections >= 0.0.0-0, < 0.2.1"],"patched":["bun_collections 0.2.1"],"published":"2026-09-20","updated":"2026-09-25","sourceUpdated":"2026-09-25T18:00:04.471289722Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/RUSTSEC-2026-0309","references":[{"url":"https://crates.io/crates/bun_collections"},{"url":"https://rustsec.org/advisories/RUSTSEC-2026-0309.html"},{"url":"https://github.com/putao520/bao/issues/46"}],"tags":["osv","rust"],"ingestedAt":"2026-09-26T07:17:57.339Z","slug":"RUSTSEC-2026-0309","body":"## Overview\n\nIn versions before 0.2.1, `SinglyLinkedList::remove` is safe and walks the intrusive list with an unchecked dereference. On an empty list, or when `node` is not in the list, `(*current_elm).next` reads a null pointer. That is undefined behavior. The list head is a raw `*mut Node<T>`, and safe code can construct the empty list.\n\nThe maintainer fixed this in 0.2.1 by rejecting those two cases with an unconditional `assert!` before the pointer is followed, matching the upstream Zig `unwrap` on the same paths. 0.2.0 was yanked. Versions 0.1.0 through 0.1.13 are still published and still contain the unchecked walk.\n\n## Affected packages\n\n- `bun_collections >= 0.0.0-0, < 0.2.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `bun_collections 0.2.1`","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}