aws-samples / aws-samples/sample-code-for-a-secure-vault-using-aws-nitro-enclaves
RUSTSEC-2025-0047: Out-of-bounds access in `get_disjoint_mut` due to incorrect bounds check
- Dominant language
- Rust
- Stars
- 9
- Forks
- 7
- PR merge metrics
- No merged PRs in 30d
Description
> Out-of-bounds access in `get_disjoint_mut` due to incorrect bounds check
| Details | |
| ------------------- | ---------------------------------------------- |
| Package | `slab` |
| Version | `0.4.10` |
| URL | [https://github.com/tokio-rs/slab/security/advisories/GHSA-qx2v-8332-m4fv](https://github.com/tokio-rs/slab/security/advisories/GHSA-qx2v-8332-m4fv) |
| Date | 2025-08-12 |
| Patched versions | `>=0.4.11` |
| Unaffected versions | `<0.4.10` |
## Impact
The `get_disjoint_mut` method in slab v0.4.10 incorrectly checked if indices were within the slab's capacity instead of its length, allowing access to uninitialized memory. This could lead to undefined behavior or potential crashes.
## Patches
This has been fixed in slab v0.4.11.
## Workarounds
Avoid using `get_disjoint_mut` with indices that might be beyond the slab's actual length, or upgrade to v0.4.11 or later.
## References
* [https://github.com/tokio-rs/slab/pull/152](https://github.com/tokio-rs/slab/pull/152)
See [advisory page](https://rustsec.org/advisories/RUSTSEC-2025-0047.html) for additional details.
Contributor guide
Research direction
Start by checking the project's dependency configuration for slab version 0.4.10 and confirm whether get_disjoint_mut is used. Update the dependency to the patched 0.4.11 or later release, then run the project's existing checks to confirm the dependency change is clean.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 38/100