RUSTSEC-2026-0309

Source
https://rustsec.org/advisories/RUSTSEC-2026-0309
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0309.json
JSON Data
https://api.test.osv.dev/v1/vulns/RUSTSEC-2026-0309
Published
2026-09-20T12:00:00Z
Modified
2026-09-25T18:00:03Z
Summary
`SinglyLinkedList::remove` dereferences a null link
Details

In versions before 0.2.1, SinglyLinkedList::remove is safe and walks the intrusive list with an unchecked dereference. On an empty list, or when node is not in the list, (*current_elm).next reads a null pointer. That is undefined behavior. The list head is a raw *mut Node<T>, and safe code can construct the empty list.

The maintainer fixed this in 0.2.1 by rejecting those two cases with an unconditional assert! before the pointer is followed, matching the upstream Zig unwrap on the same paths. 0.2.0 was yanked. Versions 0.1.0 through 0.1.13 are still published and still contain the unchecked walk.

Database specific
{
    "license": "CC0-1.0"
}
References

Affected packages

crates.io / bun_collections

Package

Name
bun_collections
View open source insights on deps.dev
Purl
pkg:cargo/bun_collections

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0-0
Fixed
0.2.1

Ecosystem specific

{
    "affected_functions": null,
    "affects": {
        "arch": [],
        "functions": [
            "bun_collections::pool::SinglyLinkedList::remove"
        ],
        "os": []
    }
}

Database specific

categories
[
    "memory-corruption"
]
cvss
null
informational
"unsound"
source
"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0309.json"