- Reported
-
- Issued
-
- Package
-
hexchat
(crates.io)
- Type
-
INFO
Unsound
- Categories
-
- Keywords
-
#memory-safety
- References
-
- Patched
-
no patched versions
Description
All versions of this crate have function deregister_command which can result in use after free.
This is unsound.
In addition, all versions since 0.3.0 have "safe" macros, which are documented as unsafe to use in threads.
In addition, the hexchat crate is no longer actively maintained. If you rely on this crate, consider switching
to an alternative.
Advisory available under CC0-1.0
license.