---
id: RUSTSEC-2024-0448
title: '`parse_arguments` reads a caller-supplied pointer as a slice'
summary: '`parse_arguments` reads a caller-supplied pointer as a slice'
severity: none
vendor: rutie
product: rutie
ecosystem: rust
affected:
  - 'rutie >= 0.14.0, < 0.14.1'
patched:
  - rutie 0.14.1
published: '2024-11-25'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T08:15:02.455721883Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/RUSTSEC-2024-0448'
references:
  - url: 'https://crates.io/crates/rutie'
  - url: 'https://rustsec.org/advisories/RUSTSEC-2024-0448.html'
  - url: 'https://github.com/danielpclark/rutie/issues/190'
tags:
  - osv
  - rust
ingestedAt: '2026-10-04T07:27:31.043Z'
---

## Overview

`parse_arguments` is safe. It takes `arguments: *const AnyObject` and `argc`, and calls `slice::from_raw_parts(arguments, argc as usize)`.

It does not check that `arguments` is non-null and aligned, or that `argc` elements are initialized. Safe Rust can pass a null pointer or a length past the allocation. The maintainer confirmed this on 2026-10-03, including a debug abort on Rust 1.78+ when Ruby calls an arity -1 method (`to_s` via `format`, `puts`, or `Array#join`) with a NULL `argv` and `argc` of 0.

## Affected packages

- `rutie >= 0.14.0, < 0.14.1`

## Remediation

Upgrade to a patched release:

- `rutie 0.14.1`
