VDB
Sign up
—

RUSTSEC-2020-0052

Undefined Behavior in bounded channel

Details

The affected version of this crate's the `bounded` channel incorrectly assumes that `Vec::from_iter` has allocated capacity that same as the number of iterator elements. `Vec::from_iter` does not actually guarantee that and may allocate extra memory. The destructor of the `bounded` channel reconstructs `Vec` from the raw pointer based on the incorrect assumes described above. This is unsound and causing deallocation with the incorrect capacity when `Vec::from_iter` has allocated different sizes with the number of iterator elements.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/crossbeam-channel
Introduced in: 0.4.3Fixed in: 0.4.4

Upgrade crossbeam-channel to 0.4.4 or newer (ecosystem crates.io).

References