GHSA-gq4h-f254-7cw9
Dashboard / Vulnerabilities / GHSA-gq4h-f254-7cw9
GHSA-gq4h-f254-7cw9
Summary: Duplicate Advisory: Data races in ticketed_lock
Details: ## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-77m6-x95j-75r5. This link is maintained to preserve external references. ## Original Description Affected versions of this crate unconditionally implemented `Send` for `ReadTicket<T>` & `WriteTicket<T>`. This allows to send non-Send `T` to other threads. This can allows creating data races by cloning types with internal mutability and sending them to other threads (as `T` of `ReadTicket<T>`/`WriteTicket<T>`). Such data races can cause memory corruption or other undefined behavior. The flaw was corrected in commit `a986a93` by adding `T: Send` bounds to `Send` impls of `ReadTicket<T>`/`WriteTicket<T>`.
References: https://github.com/kvark/ticketed_lock/issues/7, https://github.com/kvark/ticketed_lock/commit/a986a9335d591fa5c826157d1674d47aa525357f, https://rustsec.org/advisories/RUSTSEC-2020-0119.html
Affected packages
Package
Name: ticketed_lock
Purl: pkg:cargo/ticketed_lock
Affected ranges
Type: SEMVER
Events:
