RUSTSEC-2025-0167None▾ Sunlit`Bitmap::try_from(&[u8])` can create invalid values
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
The TryFrom<&[u8]> implementation for Bitmap<SIZE> copies the input bytes
into an uninitialized backing store and calls assume_init() without
validating that the bytes form a valid value of the backing store type. For
SIZE = 1 the backing store is a bool, so any input byte other than 0x00
or 0x01 produces an invalid value, which is immediate undefined behavior.
The AsMut<[u8]> implementation has the same problem, as it allows safe code
to write invalid bit patterns into the backing store through the returned slice.
No fixed version is available, as the crate is unmaintained; its GitHub repository was archived by the owner on 2026-05-03.
bitmaps >= 3.2.0Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.