GHSA-74r5-g7vc-j2v2: zerovec-derive incorrectly uses `#[repr(packed)]`
(updated )
The affected versions make unsafe memory accesses under the assumption that #[repr(packed)]
has a guaranteed field order.
The Rust specification does not guarantee this, and https://github.com/rust-lang/rust/pull/125360 (1.80.0-beta) starts
reordering fields of #[repr(packed)]
structs, leading to illegal memory accesses.
The patched versions 0.9.7
and 0.10.3
use #[repr(C, packed)]
, which guarantees field order.
References
Detect and mitigate GHSA-74r5-g7vc-j2v2 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →