GHSA-9j8q-m9x5-9g6j

    Dashboard / Vulnerabilities / GHSA-9j8q-m9x5-9g6j

    GHSA-9j8q-m9x5-9g6j

    Published: 25 Aug 2021Last Modified: 8 Nov 2023

    Summary: Data races in async-coap

    Details: An issue was discovered in the async-coap crate through 2020-12-08 for Rust. Affected versions of this crate implement Send/Sync for `ArcGuard<RC, T>` with no trait bounds on `RC`. This allows users to send `RC: !Send` to other threads and also allows users to concurrently access `Rc: !Sync` from multiple threads. This can result in memory corruption from data race or other undefined behavior caused by sending `T: !Send` to other threads (e.g. dropping `MutexGuard<T>` in another thread that didn't lock its mutex).

    Affected packages

    Package

    Name: async-coap

    Purl: pkg:cargo/async-coap

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-9j8q-m9x5-9g6j | CVE-DB