---
id: RUSTSEC-2026-0220
title: 'Uint shift operations: incorrect overflow flags and truncated shift amounts'
summary: 'Uint shift operations: incorrect overflow flags and truncated shift amounts'
severity: none
vendor: ruint
product: ruint
ecosystem: rust
affected:
  - 'ruint >= 0.0.0-0, < 1.20.0'
patched:
  - ruint 1.20.0
published: '2026-07-08'
updated: '2026-07-30'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/RUSTSEC-2026-0220'
references:
  - url: 'https://crates.io/crates/ruint'
  - url: 'https://rustsec.org/advisories/RUSTSEC-2026-0220.html'
  - url: 'https://github.com/alloy-rs/ruint/pull/603'
tags:
  - osv
  - rust
ingestedAt: '2026-07-31T19:10:08.259Z'
---

## Overview

`Uint::overflowing_shl`/`overflowing_shr` returned false-negative overflow
flags. `overflowing_shl` missed bits shifted above `BITS` but within the top
limb (non-limb-aligned widths such as `U160`), and limbs wholly discarded by
shifts >= 64; `overflowing_shr` missed wholly discarded low limbs. Shifted
values were correct; only the flag was wrong.

The wrong flag propagates: `checked_shl`/`checked_shr` return `Some` instead
of `None`, `strict_*` fail to panic, and `saturating_*` return a wrapped
value instead of saturating. The incorrect `checked_shl` result causes
`to_base_be` (and string formatting) to loop forever on no-alloc builds for
non-limb-aligned widths — a denial of service if formatting is reachable
from untrusted input.

Separately, `wrapping_shl`/`wrapping_shr` on 64/128/256-bit types truncated
the shift amount modulo 2^32, so shifts >= 2^32 returned an incorrectly
wrapped value instead of zero; on 32-bit targets the generic path also
truncated 64-bit shift amounts.

Callers using checked or saturating shift semantics on untrusted shift
amounts may compute incorrect results.

## Affected packages

- `ruint >= 0.0.0-0, < 1.20.0`

## Remediation

Upgrade to a patched release:

- `ruint 1.20.0`
