HIGH8.1
GHSA-f997-8gxg-r354
Data races in lexer
Details
lexer is a plugin based lexical reader.Affected versions of this crate implements Sync for ReaderResult<T, E> with the trait bound T: Send, E: Send. Since matching on the public enum ReaderResult<T, E> provides access to &T & &E, allowing data race to a non-Sync type T or E. This can result in a memory corruption when multiple threads concurrently access &T or &E. Suggested fix for the bug is change the trait bounds imposed on T & E to be T: Sync, E: Sync.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/lexer
Introduced in:
0No fixed version published yet for lexer. Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-36458[ADVISORY]
- https://gitlab.com/nathanfaucett/rs-lexer[PACKAGE]
- https://gitlab.com/nathanfaucett/rs-lexer/-/issues/2[WEB]
- https://raw.githubusercontent.com/rustsec/advisory-db/main/crates/lexer/RUSTSEC-2020-0138.md[WEB]
- https://rustsec.org/advisories/RUSTSEC-2020-0138.html[WEB]