unsafe-rust-review-experimental
Audited by Socket on Sep 26, 2026
12 alerts found:
Anomalyx8Securityx4No evidence of malicious behavior or obfuscation. `boundary_or` contains a serious unsafe indexing bug: for every nonempty slice it performs an out-of-bounds unchecked access, causing undefined behavior. Avoid calling it until corrected, for example by using `len - 1` or checked indexing as appropriate.
No malicious behavior is evident. The main issue is memory unsafety: the safe `callback_index` APIs permit out-of-bounds unchecked access through a caller-provided `Position` implementation. The `Lane` API also relies on an undocumented unsafe implementation contract. Validate indices or use checked indexing.
No evidence of malicious behavior or obfuscation. The code does contain several memory-safety hazards involving invalid boolean transmutation, unchecked raw-pointer reads, and unchecked slice indexing. These can cause undefined behavior if callers violate implicit pointer or bounds assumptions.
No evidence of malicious behavior. The code contains a memory-safety defect: the safe from_static/overwrite path permits writing to immutable static storage through a cast mutable pointer, causing undefined behavior. The unsafe raw-pointer constructor also relies on caller-provided validity guarantees.
No clear malicious behavior is present. local_text(false) creates an invalid &str using unchecked UTF-8 conversion, resulting in undefined behavior and a significant memory-safety defect. The delegated decoder relies on its documented unsafe caller precondition.
No evidence of malicious behavior. There is a configuration-specific memory-safety defect: callers can pass zero in burst/aarch64/arena builds, causing undefined behavior through `new_unchecked`. Validate the input in every configuration or make the API enforce the nonzero invariant.
No malicious behavior is evident. There is a configuration-specific unsafe correctness flaw: a caller can pass zero in the `burst` + `aarch64` + arena configuration, violating the `new_unchecked` precondition and causing undefined behavior. Validate the input in that branch or use the checked constructor.
The code contains a concrete unsafe-trait contract violation that causes undefined behavior when `owned` is called. This is a serious memory-safety defect, but the snippet provides no evidence of malware or intentional data theft.
No malicious behavior is present. The compact implementation has a memory-safety issue: release builds may pass surrogate values to char::from_u32_unchecked, violating its safety contract. Validate the value in all builds or use the checked conversion.
This code is not indicative of malware, but its safe API is unsound: get_mut can produce aliased mutable references, and get can overlap with a later mutable reference. This is a memory-safety vulnerability that should be corrected by tying returned reference lifetimes to the method borrow or otherwise enforcing exclusivity.
No evidence of malware or obfuscation. The function has a memory-safety flaw: because Slot is public and externally implementable, an out-of-range index can trigger undefined behavior through unchecked indexing. Validate the index or constrain the trait/API so the range is guaranteed.
No malicious behavior is evident. The function has a serious unsafe correctness defect: passing 0 reaches `unreachable_unchecked()` and causes undefined behavior. Callers must not rely on this function being safe for arbitrary u8 inputs unless the zero case is fixed or ruled out by a sound precondition.