HIGH8.1
GHSA-368f-29c3-4f2r
Data race in conqueue
Details
Affected versions of this crate unconditionally implemented `Send`/`Sync` for `QueueSender<T>`, allowing to send non-Send `T` to other threads by invoking `(&QueueSender<T>).send()`.
This fails to prevent users from creating data races by sending types like `Rc<T>` or `Arc<Cell<T>>` to other threads, which can lead to memory corruption. The flaw was corrected in commit `1e462c3` by imposing `T: Send` to both `Send`/`Sync` impls for `QueueSender<T>`/`QueueReceiver<T>`.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/conqueue
Introduced in:
0Fixed in: 0.4.0Upgrade conqueue to 0.4.0 or newer (ecosystem crates.io).
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-36437[ADVISORY]
- https://github.com/longshorej/conqueue/commit/1e462c32e7933821ddb26dc49fd4ffa5aeca97b8[WEB]
- https://github.com/longshorej/conqueue[PACKAGE]
- https://raw.githubusercontent.com/rustsec/advisory-db/main/crates/conqueue/RUSTSEC-2020-0117.md[WEB]
- https://rustsec.org/advisories/RUSTSEC-2020-0117.html[WEB]