---
id: RUSTSEC-2026-0309
title: '`SinglyLinkedList::remove` dereferences a null link'
summary: '`SinglyLinkedList::remove` dereferences a null link'
severity: none
vendor: bun_collections
product: bun_collections
ecosystem: rust
affected:
  - 'bun_collections >= 0.0.0-0, < 0.2.1'
patched:
  - bun_collections 0.2.1
published: '2026-09-20'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T18:00:04.471289722Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/RUSTSEC-2026-0309'
references:
  - url: 'https://crates.io/crates/bun_collections'
  - url: 'https://rustsec.org/advisories/RUSTSEC-2026-0309.html'
  - url: 'https://github.com/putao520/bao/issues/46'
tags:
  - osv
  - rust
ingestedAt: '2026-09-26T07:17:57.339Z'
---

## Overview

In versions before 0.2.1, `SinglyLinkedList::remove` is safe and walks the intrusive list with an unchecked dereference. On an empty list, or when `node` is not in the list, `(*current_elm).next` reads a null pointer. That is undefined behavior. The list head is a raw `*mut Node<T>`, and safe code can construct the empty list.

The maintainer fixed this in 0.2.1 by rejecting those two cases with an unconditional `assert!` before the pointer is followed, matching the upstream Zig `unwrap` on the same paths. 0.2.0 was yanked. Versions 0.1.0 through 0.1.13 are still published and still contain the unchecked walk.

## Affected packages

- `bun_collections >= 0.0.0-0, < 0.2.1`

## Remediation

Upgrade to a patched release:

- `bun_collections 0.2.1`
