HIGH8.1
GHSA-fqq2-xp7m-xvm8
Data race in ruspiro-singleton
Details
`Singleton<T>` is meant to be a static object that can be initialized lazily. In order to satisfy the requirement that `static` items must implement `Sync`, `Singleton` implemented both `Sync` and `Send` unconditionally.
This allows for a bug where non-`Sync` types such as `Cell` can be used in singletons and cause data races in concurrent programs.
The flaw was corrected in commit `b0d2bd20e` by adding trait bounds, requiring the contaiend type to implement `Sync`.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/ruspiro-singleton
Introduced in:
0Fixed in: 0.4.1Upgrade ruspiro-singleton to 0.4.1 or newer (ecosystem crates.io).
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-36435[ADVISORY]
- https://github.com/RusPiRo/ruspiro-singleton/issues/10[WEB]
- https://github.com/RusPiRo/ruspiro-singleton/pull/11[WEB]
- https://github.com/RusPiRo/ruspiro-singleton/commit/b0d2bd20eb40b9cbc2958b981ba2dcd9e6f9396e[WEB]
- https://github.com/RusPiRo/ruspiro-singleton[PACKAGE]
- https://raw.githubusercontent.com/rustsec/advisory-db/main/crates/ruspiro-singleton/RUSTSEC-2020-0115.md[WEB]
- https://rustsec.org/advisories/RUSTSEC-2020-0115.html[WEB]