{"id":"GHSA-xqjr-wfx3-gmxv","aliases":["RUSTSEC-2025-0054"],"url":"https://o3.security/vulnerability/GHSA-xqjr-wfx3-gmxv","summary":"ArrayQueue's push_front is not panic-safe","details":"The safe API `array_queue::ArrayQueue::push_front` can lead to deallocating uninitialized memory if a panic occurs while invoking the `clone` method on the passed argument.\n\nSpecifically, `push_front` receives an argument that is intended to be cloned and pushed, whose type implements the `Clone` trait. Furthermore, the method updates the queue's `start` index before initializing the slot for the newly pushed element. User-defined implementations of `Clone` may include a `clone` method that can panic. If such a panic occurs during initialization, the structure is left with an advanced `start` index pointing to an uninitialized slot. When `ArrayQueue` is later dropped, its destructor treats that slot as initialized and attempts to drop it, resulting in an attempt to free uninitialized memory.\n\nThe bug was fixed in commit `728fe1b`.","published":"2025-09-02T17:35:16Z","modified":"2025-10-28T06:29:27.045607Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"array-queue","fixedVersion":"0.4.0"}],"fix":{"url":"https://github.com/raviqqe/array-queue/commit/728fe1bdffb04896d218e962d989a2ae6bf1ea92","label":"raviqqe/array-queue@728fe1b"},"references":[{"type":"WEB","url":"https://github.com/raviqqe/array-queue/issues/3"},{"type":"WEB","url":"https://github.com/raviqqe/array-queue/commit/728fe1bdffb04896d218e962d989a2ae6bf1ea92"},{"type":"PACKAGE","url":"https://github.com/raviqqe/array-queue"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2025-0054.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-10-28T06:29:27.045607Z"}}