Files
advisory-db/crates/dces/RUSTSEC-2020-0139.md
2021-01-30 23:02:50 -05:00

515 B

[advisory]
id = "RUSTSEC-2020-0139"
package = "dces"
date = "2020-12-09"
url = "https://gitlab.redox-os.org/redox-os/dces-rust/-/issues/8"
categories = ["memory-corruption", "thread-safety"]
keywords = ["concurrency"]

[versions]
patched = []

dces' World type can cause data races

The World type in dces is marked as Send without bounds on its EntityStore and ComponentStore.

This allows non-thread safe EntityStore and ComponentStores to be sent across threads and cause data races.