RUSTSEC-2026-0204: Invalid pointer dereference in `fmt::Pointer` impl for `Atomic` and `Shared` when the underlying pointer is invalid
Nobody has claimed this yet.
- Dominant language
- Rust
- Stars
- 147
- Forks
- 39
- Avg merge
- 16h 39m
- Merged PRs (30d)
- 2
Description
Invalid pointer dereference in
fmt::Pointerimpl forAtomicandSharedwhen the underlying pointer is invalid
| Details | |
|---|---|
| Package | crossbeam-epoch |
| Version | 0.9.18 |
| URL | https://github.com/crossbeam-rs/crossbeam/pull/1276 |
| Date | 2026-07-06 |
| Patched versions | >=0.9.20 |
| Unaffected versions | <0.9.0 |
Affected versions of fmt::Display dereference the underlying pointer. This causes a invalid pointer dereference e.g., when a pointer created with Atomic::null or Shared::null. fmt::Debug impls and pre-0.9 fmt::Display impls, which do not dereference pointers, are not affected by this issue.
See advisory page for additional details.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No project file or test is named in the report. Start by locating the dependency declaration for crossbeam-epoch and checking how version 0.9.18 is used. Update it to a patched version at least 0.9.20, then run the project's existing checks to confirm the dependency still works.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 72/100