—
RUSTSEC-2025-0023
Broadcast channel calls clone in parallel, but does not require `Sync`
Details
The broadcast channel internally calls `clone` on the stored value when receiving it, and only requires `T:Send`. This means that using the broadcast channel with values that are `Send` but not `Sync` can trigger unsoundness if the `clone` implementation makes use of the value being `!Sync`.
Thank you to Austin Bonander for finding and reporting this issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/tokio
Introduced in:
0.2.5Fixed in: 1.38.2Upgrade tokio to 1.38.2 or newer (ecosystem crates.io).