GHSA-rmff-f8w9-c9rm
Dashboard / Vulnerabilities / GHSA-rmff-f8w9-c9rm
GHSA-rmff-f8w9-c9rm
Summary: Data races in max7301
Details: The `ImmediateIO` and `TransactionalIO` types implement `Sync` for all contained `Expander<EI>` types regardless of if the `Expander` itself is safe to use across threads. As the `IO` types allow retrieving the `Expander`, this can lead to non-thread safe types being sent across threads as part of the `Expander` leading to data races.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-36472, https://github.com/edarc/max7301/issues/1, https://github.com/edarc/max7301/commit/0a1da873ddb29bca926bad8301f8d7ab8aa97c52, https://github.com/edarc/max7301, https://rustsec.org/advisories/RUSTSEC-2020-0152.html
Affected packages
Package
Name: max7301
Purl: pkg:cargo/max7301
Affected ranges
Type: SEMVER
Events:
