MEDIUM5.5
GHSA-p9m5-3hj7-cp5r
futures_task::noop_waker_ref can segfault due to dereferencing a NULL pointer
Details
Affected versions of the crate used a UnsafeCell in thread-local storage to return a noop waker reference, assuming that the reference would never be returned from another thread.
This resulted in a segmentation fault crash if Waker::wake_by_ref() was called on a waker returned from another thread due to it attempting to dereference a pointer that wasn't accessible from the main thread.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/futures-task
Introduced in:
0Fixed in: 0.3.5Upgrade futures-task to 0.3.5 or newer (ecosystem crates.io).