RUSTSEC-2024-0448None▾ Sunlit`parse_arguments` reads a caller-supplied pointer as a slice
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
parse_arguments is safe. It takes arguments: *const AnyObject and argc, and calls slice::from_raw_parts(arguments, argc as usize).
It does not check that arguments is non-null and aligned, or that argc elements are initialized. Safe Rust can pass a null pointer or a length past the allocation. The maintainer confirmed this on 2026-10-03, including a debug abort on Rust 1.78+ when Ruby calls an arity -1 method (to_s via format, puts, or Array#join) with a NULL argv and argc of 0.
rutie >= 0.14.0, < 0.14.1Upgrade to a patched release:
rutie 0.14.1