MEDIUM
GHSA-c8v3-jhv9-4ppc
Use-after-free when setting the locale
Details
Version 3.0.0 introduced an `AtomicStr` type, that is used to store the current locale. It stores the locale as a raw pointer to an `Arc<String>`. The locale can be read with `AtomicStr::as_str()`. `AtomicStr::as_str()` does not increment the usage counter of the `Arc`.
If the locale is changed in one thread, another thread can have a stale -- possibly already freed -- reference to the stored string.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/rust-i18n-support
Introduced in:
3.0.0Fixed in: 3.0.1Upgrade rust-i18n-support to 3.0.1 or newer (ecosystem crates.io).