VDB
Sign up
MEDIUM

GHSA-c8v3-jhv9-4ppc

Use-after-free when setting the locale

Details

Version 3.0.0 introduced an `AtomicStr` type, that is used to store the current locale. It stores the locale as a raw pointer to an `Arc<String>`. The locale can be read with `AtomicStr::as_str()`. `AtomicStr::as_str()` does not increment the usage counter of the `Arc`.

If the locale is changed in one thread, another thread can have a stale -- possibly already freed -- reference to the stored string.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/rust-i18n-support
Introduced in: 3.0.0Fixed in: 3.0.1

Upgrade rust-i18n-support to 3.0.1 or newer (ecosystem crates.io).

References