VDB
Sign up
MEDIUM

GHSA-w59h-378f-2frm

Unsound sending of non-Send types across threads in threadalone

Details

Affected versions can run the `Drop` impl of a non-Send type on a different thread than it was created on.

The flaw occurs when a stderr write performed by the `threadalone` crate fails, for example because stderr is redirected to a location on a filesystem that is full, or because stderr is a pipe that has been closed by the reader.

Dropping a non-Send type on the wrong thread is unsound. If used with a type such as a pthread-based `MutexGuard`, [the consequence is undefined behavior][mutexguard]. If used with `Rc`, there would be a data race on the reference count, which is likewise undefined behavior.

[mutexguard]: https://github.com/rust-lang/rust/issues/23465#issuecomment-82730326

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/threadalone
Introduced in: 0Fixed in: 0.2.1

Upgrade threadalone to 0.2.1 or newer (ecosystem crates.io).

References