VDB
Sign up
LOW

GHSA-mc8h-8q98-g5hr

Race Condition Enabling Link Following and Time-of-check Time-of-use (TOCTOU) Race Condition in remove_dir_all

Details

The `remove_dir_all` crate is a Rust library that offers additional features over the Rust standard library `fs::remove_dir_all` function. It suffers the same class of failure as the code it was layering over: TOCTOU race conditions, with the ability to cause arbitrary paths to be deleted by substituting a symlink for a path after the type of the path was checked.

Thanks to the Rust security team for identifying the problem and alerting us to it.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/remove_dir_all
Introduced in: 0Fixed in: 0.8.0

Upgrade remove_dir_all to 0.8.0 or newer (ecosystem crates.io).

References