🛡️ RUSTSEC-2023-0126 — im
Description
Aliasing violation in OrdSet insertion
Inserting into an im::OrdSet (for example by collecting an iterator into one) can violate
Rust's aliasing rules: Miri reports a stacked borrows violation in
sized_chunks::Chunk::force_copy(), which is called during insertion, where a shared borrow
is invalidated by a unique borrow before the read through it completes.
This is undefined behavior, reachable from safe code.
No fixed version is available, as the crate is unmaintained; its GitHub
repository was archived by the owner on 2026-05-03.
Affected software
RUSTSEC-2023-0126 is recorded against 1 package.
- im
Timeline and source
Published on 4 February 2023 and last revised on 10 August 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
crates.io (Package)
rustsec.org (Advisory)
github.com (Report)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| im | — | — |
References
Similar Threats
- Unknown RUSTSEC-2026-0248
- Unknown RUSTSEC-2026-0250
- Medium CVE-2026-33812
- High CVE-2026-33813
- Critical CVE-2025-66480
More RUSTSEC 2023 advisories
Browse all of RUSTSEC 2023 in the advisory index.
Free Vulnerability Check
Is your site affected by RUSTSEC-2023-0126?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against RUSTSEC-2023-0126 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.