RUSTSEC-2020-0119
Dashboard / Vulnerabilities / RUSTSEC-2020-0119
RUSTSEC-2020-0119
Summary: ReadTicket and WriteTicket should only be sendable when T is Send
Details: Affected versions of this crate unconditionally implemented `Send` for `ReadTicket<T>` & `WriteTicket<T>`. This allows to send non-Send `T` to other threads. This can allows creating data races by cloning types with internal mutability and sending them to other threads (as `T` of `ReadTicket<T>`/`WriteTicket<T>`). Such data races can cause memory corruption or other undefined behavior. The flaw was corrected in commit a986a93 by adding `T: Send` bounds to `Send` impls of `ReadTicket<T>`/`WriteTicket<T>`.
References: https://crates.io/crates/ticketed_lock, https://rustsec.org/advisories/RUSTSEC-2020-0119.html, https://github.com/kvark/ticketed_lock/issues/7
Affected packages
Package
Name: ticketed_lock
Purl: pkg:cargo/ticketed_lock
Affected ranges
Type: SEMVER
Events:
