Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9mxw-4856-9cm5

Опубликовано: 25 авг. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7

Описание

Data races in rusb

Affected versions of rusb did not require UsbContext to implement Send and Sync. However, through Device and DeviceHandle it is possible to use UsbContexts across threads. This issue allows non-thread safe UsbContext types to be used concurrently leading to data races and memory corruption. The issue was fixed by adding Send and Sync bounds to UsbContext.

Пакеты

Наименование

rusb

rust
Затронутые версииВерсия исправления

< 0.7.0

0.7.0

EPSS

Процентиль: 21%
0.00068
Низкий

7 High

CVSS3

Дефекты

CWE-662
CWE-787

Связанные уязвимости

CVSS3: 7
nvd
около 5 лет назад

An issue was discovered in the rusb crate before 0.7.0 for Rust. Because of a lack of Send and Sync bounds, a data race and memory corruption can occur.

EPSS

Процентиль: 21%
0.00068
Низкий

7 High

CVSS3

Дефекты

CWE-662
CWE-787