GHSA-48m6-wm5p-rr6h
Dashboard / Vulnerabilities / GHSA-48m6-wm5p-rr6h
Summary: Insufficient covariance check makes self_cell unsound
Details: All public versions prior to `1.02` used an insufficient check to ensure that users correctly marked the dependent type as either `covariant` or `not_covariant`. This allowed users to mark a dependent as covariant even though its type was not covariant but invariant, for certain invariant types involving trait object lifetimes. One example for such a dependent type is `type Dependent<'a> = RefCell<Box<dyn fmt::Display + 'a>>`. Such a type allowed unsound usage in purely safe user code that leads to undefined behavior. The patched versions now produce a compile time error if such a type is marked as `covariant`.
References: https://github.com/Voultapher/self_cell/issues/49, https://github.com/Voultapher/self_cell, https://rustsec.org/advisories/RUSTSEC-2023-0070.html
Affected packages
Package
Name: self_cell
Purl: pkg:cargo/self_cell
Affected ranges
Type: SEMVER
Events:
