An issue was discovered in the xcb crate through 2021-02-04 for Rust. It has a soundness violation because xcb::xproto::GetAtomNameReply::name() calls std::str::fromutf8unchecked() on unvalidated bytes from an X server.
{ "binaries": [ { "binary_name": "librust-xcb+debug-all-dev", "binary_version": "0.9.0-2" }, { "binary_name": "librust-xcb+present-dev", "binary_version": "0.9.0-2" }, { "binary_name": "librust-xcb+x11-dev", "binary_version": "0.9.0-2" }, { "binary_name": "librust-xcb+xfixes-dev", "binary_version": "0.9.0-2" }, { "binary_name": "librust-xcb+xlib-xcb-dev", "binary_version": "0.9.0-2" }, { "binary_name": "librust-xcb-dev", "binary_version": "0.9.0-2" } ] }