GCWing / GCWing/OpenBitFun

[Security]: RUSTSEC-2026-0253: lru 0.12.5 in Cargo.lock is unsound (use-after-free via LruCache eviction)

オープン
#2,587 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
Rust
スター
2.3k
フォーク
231
平均マージ
2時間 46分
マージ済み PR(30日)
577

説明

### Summary

`lru` 0.12.5 — the version locked in `Cargo.lock` on `main`, pulled in
by `ratatui 0.29` — is covered by RUSTSEC-2026-0253 (later advisories
reference RUSTSEC-2026-0002): `LruCache::pop` is not panic-safe, and an
eviction that panics can leave the cache in an inconsistent state,
leading to a use-after-free or double free. The advisory is fixed in
`lru` >= 0.18.2, which `ratatui 0.29` cannot satisfy because it pins
`lru ^0.12`.

### Affected dependency chain

- `ratatui 0.29.0` (locked in `Cargo.lock`, CLI TUI startup path)
- `-> lru 0.12.5` (locked; affected range)

### Reproduction (from a clean checkout)

1. `git clone` the repository and check out `main`.
2. Run `cargo audit` (or `cargo deny check advisories`).
3. Observed: `lru` flagged as unsound at 0.12.5 (RUSTSEC-2026-0253),
with the advisory requiring `lru >= 0.18.2`.

### Suggested fix

Upgrade `ratatui` from 0.29 to 0.30 (whose `ratatui-core` requires
`lru ^0.18`, resolving the advisory), relax the `bitflags` pin from
`=2.11.1` to `^2` as required by `ratatui-core 0.1.2`, and carry the
small `Backend` trait adaptation in the CLI startup loop. I have a patch
ready and will open a PR referencing this issue.

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

Start with Cargo.lock and the dependency declarations that pull in ratatui 0.29, then run cargo audit or cargo deny check advisories from a clean checkout. Upgrade the dependency chain, inspect the CLI startup loop for the required Backend trait adaptation, and confirm the advisory is no longer reported and the project checks pass.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
rust
領域
cli, security
issue の種類
バグ
難易度
3/5
見積もり時間
1〜2日
活発さ
活発
明瞭さ
明確に書かれている
初心者へのやさしさ
35/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。