RUSTSEC-2020-0094
Dashboard / Vulnerabilities / RUSTSEC-2020-0094
RUSTSEC-2020-0094
Summary: Unsound: can make `ARefss` contain a !Send, !Sync object.
Details: `ARefss<'a, V>` is a type that is assumed to contain objects that are `Send + Sync`. In the affected versions of this crate, `Send`/`Sync` traits are unconditionally implemented for `ARefss<'a, V>`. By using the `ARefss::map()` API, we can insert a `!Send` or `!Sync` object into `ARefss<'a, V>`. After that, it is possible to create a data race to the inner object of `ARefss<'a, V>`, which can lead to undefined behavior & memory corruption. The flaw was corrected in commit 6dd7ca0 (https://github.com/diwic/reffers-rs/commit/6dd7ca0d50f2464df708975cdafcfaeeb6d41c66) by adding trait bound `V: Send + Sync` to `ARefss::map()` API.
References: https://crates.io/crates/reffers, https://rustsec.org/advisories/RUSTSEC-2020-0094.html, https://github.com/diwic/reffers-rs/issues/7
Affected packages
Package
Name: reffers
Purl: pkg:cargo/reffers
Affected ranges
Type: SEMVER
Events:
