GHSA-p9m5-3hj7-cp5r
Dashboard / Vulnerabilities / GHSA-p9m5-3hj7-cp5r
GHSA-p9m5-3hj7-cp5r
Summary: futures_task::noop_waker_ref can segfault due to dereferencing a NULL pointer
Details: Affected versions of the crate used a UnsafeCell in thread-local storage to return a noop waker reference, assuming that the reference would never be returned from another thread. This resulted in a segmentation fault crash if Waker::wake_by_ref() was called on a waker returned from another thread due to it attempting to dereference a pointer that wasn't accessible from the main thread.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-35907, https://github.com/rust-lang/futures-rs/issues/2091, https://github.com/rust-lang/futures-rs, https://rustsec.org/advisories/RUSTSEC-2020-0061.html
Affected packages
Package
Name: futures-task
Purl: pkg:cargo/futures-task
Affected ranges
Type: SEMVER
Events:
