RUSTSEC-2024-0007
Dashboard / Vulnerabilities / RUSTSEC-2024-0007
Summary: Use-after-free when setting the locale
Details: Version 3.0.0 introduced an `AtomicStr` type, that is used to store the current locale. It stores the locale as a raw pointer to an `Arc<String>`. The locale can be read with `AtomicStr::as_str()`. `AtomicStr::as_str()` does not increment the usage counter of the `Arc`. If the locale is changed in one thread, another thread can have a stale -- possibly already freed -- reference to the stored string.
References: https://crates.io/crates/rust-i18n-support, https://rustsec.org/advisories/RUSTSEC-2024-0007.html, https://github.com/longbridgeapp/rust-i18n/issues/71, https://github.com/longbridgeapp/rust-i18n/pull/72, https://github.com/longbridgeapp/rust-i18n/releases/tag/v3.0.1
Affected packages
Package
Name: rust-i18n-support
Purl: pkg:cargo/rust-i18n-support
Affected ranges
Type: SEMVER
Events:
