RUSTSEC-2021-0036

Intern: Data race allowed on T

Issued
Package
internment (crates.io)
Type
Vulnerability
Categories
  • thread-safety
Aliases
Details
https://github.com/droundy/internment/issues/20
Patched
  • >=0.4.2

Description

Affected versions of this crate unconditionally implements Sync for Intern<T>. This allows users to create data race on T: !Sync, which may lead to undefined behavior (for example, memory corruption).

The flaw was corrected in commit 2928a87 by adding the trait bound T: Sync in the Sync impl of Intern<T>.

More