VDB
Sign up
HIGH7.8

GHSA-r93v-9p5q-vhpf

futures_task::waker may cause a use-after-free if used on a type that isn't 'static

Details

Affected versions of the crate did not properly implement a 'static lifetime bound on the waker function. This resulted in a use-after-free if Waker::wake() is called after original data had been dropped.

The flaw was corrected by adding 'static lifetime bound to the data waker takes.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/futures-task
Introduced in: 0.2.1Fixed in: 0.3.6

Upgrade futures-task to 0.3.6 or newer (ecosystem crates.io).

References