RUSTSEC-2020-0124
Dashboard / Vulnerabilities / RUSTSEC-2020-0124
RUSTSEC-2020-0124
Summary: ArcGuard's Send and Sync should have bounds on RC
Details: Affected versions of this crate implement Send/Sync for `ArcGuard<RC, T>` with no trait bounds on `RC`. This allows users to send `RC: !Send` to other threads and also allows users to concurrently access `Rc: !Sync` from multiple threads. This can result in memory corruption from data race or other undefined behavior caused by sending `T: !Send` to other threads (e.g. dropping `MutexGuard<T>` in another thread that didn't lock its mutex).
References: https://crates.io/crates/async-coap, https://rustsec.org/advisories/RUSTSEC-2020-0124.html, https://github.com/google/rust-async-coap/issues/33
Affected packages
Package
Name: async-coap
Purl: pkg:cargo/async-coap
Affected ranges
Type: SEMVER
Events:
