VDB
Sign up
HIGH8.1

GHSA-368f-29c3-4f2r

Data race in conqueue

Details

Affected versions of this crate unconditionally implemented `Send`/`Sync` for `QueueSender<T>`, allowing to send non-Send `T` to other threads by invoking `(&QueueSender<T>).send()`.

This fails to prevent users from creating data races by sending types like `Rc<T>` or `Arc<Cell<T>>` to other threads, which can lead to memory corruption. The flaw was corrected in commit `1e462c3` by imposing `T: Send` to both `Send`/`Sync` impls for `QueueSender<T>`/`QueueReceiver<T>`.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/conqueue
Introduced in: 0Fixed in: 0.4.0

Upgrade conqueue to 0.4.0 or newer (ecosystem crates.io).

References