HIGH8.1
GHSA-77m6-x95j-75r5
Data races in ticketed_lock
Details
Affected versions of this crate unconditionally implemented Send for ReadTicket<T> & WriteTicket<T>. This allows to send non-Send T to other threads. This can allows creating data races by cloning types with internal mutability and sending them to other threads (as T of ReadTicket<T>/WriteTicket<T>). Such data races can cause memory corruption or other undefined behavior. The flaw was corrected in commit `a986a93` by adding T: Send bounds to Send impls of ReadTicket<T>/WriteTicket<T>.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/ticketed_lock
Introduced in:
0Fixed in: 0.3.0Upgrade ticketed_lock to 0.3.0 or newer (ecosystem crates.io).
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-36439[ADVISORY]
- https://github.com/kvark/ticketed_lock/issues/7[WEB]
- https://github.com/kvark/ticketed_lock/commit/a986a9335d591fa5c826157d1674d47aa525357f[WEB]
- https://github.com/kvark/ticketed_lock[WEB]
- https://raw.githubusercontent.com/rustsec/advisory-db/main/crates/ticketed_lock/RUSTSEC-2020-0119.md[WEB]
- https://rustsec.org/advisories/RUSTSEC-2020-0119.html[WEB]