{"id":"GHSA-66p5-j55p-32r9","summary":"smallvec creates uninitialized value of any type","details":"Affected versions of this crate called `mem::uninitialized()` to create values of a user-supplied type `T`.\nThis is unsound e.g. if `T` is a reference type (which must be non-null and thus may not remain uninitialized).\n \nThe flaw was corrected by avoiding the use of `mem::uninitialized()`, using `MaybeUninit` instead.\n","aliases":["CVE-2018-25023","GHSA-55m5-whcv-c49c","RUSTSEC-2018-0018"],"modified":"2023-11-01T04:49:24.709547Z","published":"2021-08-25T21:00:25Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2021-08-06T16:36:54Z","nvd_published_at":null,"cwe_ids":["CWE-457"]},"references":[{"type":"WEB","url":"https://github.com/servo/rust-smallvec/issues/126"},{"type":"WEB","url":"https://github.com/servo/rust-smallvec/pull/162"},{"type":"PACKAGE","url":"https://github.com/servo/rust-smallvec"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2018-0018.html"}],"affected":[{"package":{"name":"smallvec","ecosystem":"crates.io","purl":"pkg:cargo/smallvec"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.6.13"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/08/GHSA-66p5-j55p-32r9/GHSA-66p5-j55p-32r9.json"}}],"schema_version":"1.9.0"}