RUSTSEC-2020-0127
Dashboard / Vulnerabilities / RUSTSEC-2020-0127
RUSTSEC-2020-0127
Summary: SyncRef's clone() and debug() allow data races
Details: Affected versions of this crate unconditionally implement `Sync` for `SyncRef<T>`. This definition allows data races if `&T` is accessible through `&SyncRef`. `SyncRef<T>` derives `Clone` and `Debug`, and the default implementations of those traits access `&T` by invoking `T::clone()` & `T::fmt()`. It is possible to create data races & undefined behavior by concurrently invoking `SyncRef<T>::clone()` or `SyncRef<T>::fmt()` from multiple threads with `T: !Sync`.
References: https://crates.io/crates/v9, https://rustsec.org/advisories/RUSTSEC-2020-0127.html, https://github.com/purpleposeidon/v9/issues/1, https://github.com/purpleposeidon/v9/commit/18847c50e5d36561cc91c996c3539ddb1eacf6c7
Affected packages
Package
Name: v9
Purl: pkg:cargo/v9
Affected ranges
Type: SEMVER
Events:
