HIGH8.1
GHSA-686h-j8r8-wmfm
Data races in rcu_cell
Details
Affected versions of this crate unconditionally implement Send/Sync for `RcuCell<T>`. This allows users to send `T: !Send` to other threads (while `T` enclosed within `RcuCell<T>`), and allows users to concurrently access `T: !Sync` by using the APIs of `RcuCell<T>` that provide access to `&T`.
This can result in memory corruption caused by data races.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/rcu_cell
Introduced in:
0Fixed in: 0.1.9Upgrade rcu_cell to 0.1.9 or newer (ecosystem crates.io).
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-36451[ADVISORY]
- https://github.com/Xudong-Huang/rcu_cell/issues/3[WEB]
- https://github.com/Xudong-Huang/rcu_cell/pull/4[WEB]
- https://github.com/Xudong-Huang/rcu_cell/pull/4/commits/1faf18eee11f14969b77ae0f76dcd9ebd437d0c2[WEB]
- https://github.com/Xudong-Huang/rcu_cell[PACKAGE]
- https://rustsec.org/advisories/RUSTSEC-2020-0131.html[WEB]