GHSA-ghc8-5cgm-5rpf
Inventory fails to prohibit standard library access prior to initialization of Rust standard library runtime
Details
Affected versions allow arbitrary caller-provided code to execute before the lifetime of `main`.
If the caller-provided code accesses particular pieces of the standard library that require an initialized Rust runtime, such as `std::io` or `std::thread`, these may not behave as documented. Panics are likely; UB is possible.
The flaw was corrected by enforcing that only code written within the `inventory` crate, which is guaranteed not to access runtime-dependent parts of the standard library, runs before `main`. Caller-provided code is restricted to running at compile time.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 0.2.0Upgrade inventory to 0.2.0 or newer (ecosystem crates.io).