VDB
Sign up
MEDIUM

GHSA-ghc8-5cgm-5rpf

Inventory fails to prohibit standard library access prior to initialization of Rust standard library runtime

Details

Affected versions allow arbitrary caller-provided code to execute before the lifetime of `main`.

If the caller-provided code accesses particular pieces of the standard library that require an initialized Rust runtime, such as `std::io` or `std::thread`, these may not behave as documented. Panics are likely; UB is possible.

The flaw was corrected by enforcing that only code written within the `inventory` crate, which is guaranteed not to access runtime-dependent parts of the standard library, runs before `main`. Caller-provided code is restricted to running at compile time.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/inventory
Introduced in: 0Fixed in: 0.2.0

Upgrade inventory to 0.2.0 or newer (ecosystem crates.io).

References