smallbitvec is a growable bit-vector for Rust, optimized for size. From 1.0.1 to 2.6.0, an integer overflow in the internal capacity calculation of smallbitvec can lead to an undersized heap allocation, resulting in a heap buffer overflow through safe APIs only. This allows memory corruption without requiring unsafe code from the caller. This vulnerability is fixed in 2.6.1.
Metrics
Affected Vendors & Products
References
History
Tue, 26 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | smallbitvec is a growable bit-vector for Rust, optimized for size. From 1.0.1 to 2.6.0, an integer overflow in the internal capacity calculation of smallbitvec can lead to an undersized heap allocation, resulting in a heap buffer overflow through safe APIs only. This allows memory corruption without requiring unsafe code from the caller. This vulnerability is fixed in 2.6.1. | |
| Title | smallbitvec: Safe API Triggered Heap Buffer Overflow via Integer Overflow | |
| Weaknesses | CWE-122 CWE-190 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-05-26T21:38:13.753Z
Updated: 2026-05-26T21:38:13.753Z
Reserved: 2026-05-08T16:23:33.264Z
Link: CVE-2026-44983
No data.
Status : Received
Published: 2026-05-26T22:16:43.440
Modified: 2026-05-26T22:16:43.440
Link: CVE-2026-44983
No data.