{"id":"GHSA-9fjq-45qv-pcm7","summary":"ruint affected by unsoundness of safe `reciprocal_mg10`","details":"The function `reciprocal_mg10` is marked as safe but can trigger undefined behavior (out-of-bounds access) because it relies on `debug_assert!` for safety checks instead of `assert!`.\n\nWhen compiled in release mode, the `debug_assert!` is optimized out, potentially allowing invalid inputs to cause memory corruption.","aliases":["RUSTSEC-2025-0137"],"modified":"2025-12-27T05:41:16.165671Z","published":"2025-12-26T18:55:53Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-12-26T18:55:53Z","nvd_published_at":null,"cwe_ids":["CWE-119"]},"references":[{"type":"WEB","url":"https://github.com/recmo/uint/issues/550"},{"type":"PACKAGE","url":"https://github.com/recmo/uint"},{"type":"WEB","url":"https://github.com/recmo/uint/blob/17c9b3e9062f74a39701e68dec358375595d33d7/src/algorithms/div/reciprocal.rs#L79-L87"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2025-0137.html"}],"affected":[{"package":{"name":"ruint","ecosystem":"crates.io","purl":"pkg:cargo/ruint"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"1.17.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-9fjq-45qv-pcm7/GHSA-9fjq-45qv-pcm7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"}]}