VDB
Sign up
LOW

GHSA-4q83-7cq4-p6wg

`tokio::io::ReadHalf<T>::unsplit` is Unsound

Details

`tokio::io::ReadHalf<T>::unsplit` can violate the `Pin` contract

The soundness issue is described in the [tokio/issues#5372](https://github.com/tokio-rs/tokio/issues/5372)

Specific set of conditions needed to trigger an issue (a !Unpin type in ReadHalf) is unusual, combined with the difficulty of making any arbitrary use-after-free exploitable in Rust without doing a lot of careful alignment of data types in the surrounding code.

The `tokio` feature `io-util` is also required to be enabled to trigger this soundness issue.

Thanks to zachs18 reporting the issue to Tokio team responsibly and taiki-e and carllerche appropriately responding and fixing the soundness bug.

Tokio before 0.2.0 used `futures` 0.1 that did not have `Pin`, so it is not affected by this issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/tokio
Introduced in: 1.21.0Fixed in: 1.24.2

Upgrade tokio to 1.24.2 or newer (ecosystem crates.io).

crates.io/tokio
Introduced in: 1.19.0Fixed in: 1.20.4

Upgrade tokio to 1.20.4 or newer (ecosystem crates.io).

crates.io/tokio
Introduced in: 0.2.0Fixed in: 1.18.5

Upgrade tokio to 1.18.5 or newer (ecosystem crates.io).

References