RUSTSEC-2022-0040
Dashboard / Vulnerabilities / RUSTSEC-2022-0040
Summary: Multiple soundness issues in `owning_ref`
Details: - `OwningRef::map_with_owner` is [unsound](https://github.com/Kimundi/owning-ref-rs/issues/77) and may result in a use-after-free. - `OwningRef::map` is [unsound](https://github.com/Kimundi/owning-ref-rs/issues/71) and may result in a use-after-free. - `OwningRefMut::as_owner` and `OwningRefMut::as_owner_mut` are [unsound](https://github.com/Kimundi/owning-ref-rs/issues/61) and may result in a use-after-free. - The crate [violates Rust's aliasing rules](https://github.com/Kimundi/owning-ref-rs/issues/49), which may cause miscompilations on recent compilers that emit the LLVM `noalias` attribute. `safer_owning_ref` is a replacement crate which fixes these issues. No patched versions of the original crate are available, and the maintainer is unresponsive.
References: https://crates.io/crates/owning_ref, https://rustsec.org/advisories/RUSTSEC-2022-0040.html, https://github.com/noamtashma/owning-ref-unsoundness, https://github.com/Kimundi/owning-ref-rs/issues/49, https://github.com/Kimundi/owning-ref-rs/issues/61, https://github.com/Kimundi/owning-ref-rs/issues/71, https://github.com/Kimundi/owning-ref-rs/issues/77
Affected packages
Package
Name: owning_ref
Purl: pkg:cargo/owning_ref
Affected ranges
Type: SEMVER
Events:
