Intel

AIKIDO-2026-10788

arrow-buffer is vulnerable to Denial of Service

Denial of Service Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published May 8, 2026

65

Medium Risk

This Affects:

RUSTarrow-buffer
58.0.0 - 58.1.0
Fixed in 58.2.0
Are you affected? Scan for Free

TL;DR

MutableBuffer growth and related buffer helpers used unchecked usize arithmetic when sizing reservations and zero extensions, so extreme lengths could wrap in optimized builds and undermine capacity accounting before allocation. Iterator helpers such as BitChunks could also mis-handle slice lengths when arithmetic overflowed. The release replaces those paths with checked arithmetic and tighter validation so hostile or accidental huge sizes fail deterministically instead of risking inconsistent buffer state or crashes.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

arrow-buffer is vulnerable to Denial of Service in versions 58.0.0 - 58.1.0.

How to fix this

Upgrade the arrow-buffer library to the patch version.