From 064d4a4c6f0cf6f286c3371341de3394606b8284 Mon Sep 17 00:00:00 2001 From: JOE1994 Date: Mon, 25 Jan 2021 18:02:41 -0500 Subject: [PATCH] Report 0057-async-coap to RustSec --- crates/async-coap/RUSTSEC-0000-0000.md | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) create mode 100644 crates/async-coap/RUSTSEC-0000-0000.md diff --git a/crates/async-coap/RUSTSEC-0000-0000.md b/crates/async-coap/RUSTSEC-0000-0000.md new file mode 100644 index 0000000..eb29803 --- /dev/null +++ b/crates/async-coap/RUSTSEC-0000-0000.md @@ -0,0 +1,17 @@ +```toml +[advisory] +id = "RUSTSEC-0000-0000" +package = "async-coap" +date = "2020-12-08" +url = "https://github.com/google/rust-async-coap/issues/33" +categories = ["memory-corruption"] + +[versions] +patched = [] +``` + +# ArcGuard's Send and Sync should have bounds on RC + +Affected versions of this crate implement Send/Sync for `ArcGuard` with no trait bounds on `RC`. This allows users to send `RC: !Send` to other threads and also allows users to concurrently access `Rc: !Sync` from multiple threads. + +This can result in memory corruption from data race or other undefined behavior caused by sending `T: !Send` to other threads (e.g. dropping `MutexGuard` in another thread that didn't lock its mutex).