RUSTSEC-2020-0115
Dashboard / Vulnerabilities / RUSTSEC-2020-0115
RUSTSEC-2020-0115
Summary: Singleton lacks bounds on Send and Sync.
Details: `Singleton<T>` is meant to be a static object that can be initialized lazily. In order to satisfy the requirement that `static` items must implement `Sync`, `Singleton` implemented both `Sync` and `Send` unconditionally. This allows for a bug where non-`Sync` types such as `Cell` can be used in singletons and cause data races in concurrent programs. The flaw was corrected in commit `b0d2bd20e` by adding trait bounds, requiring the contaiend type to implement `Sync`.
References: https://crates.io/crates/ruspiro-singleton, https://rustsec.org/advisories/RUSTSEC-2020-0115.html, https://github.com/RusPiRo/ruspiro-singleton/issues/10
Affected packages
Package
Name: ruspiro-singleton
Purl: pkg:cargo/ruspiro-singleton
Affected ranges
Type: SEMVER
Events:
