Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r93v-9p5q-vhpf

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.8

Описание

futures_task::waker may cause a use-after-free if used on a type that isn't 'static

Affected versions of the crate did not properly implement a 'static lifetime bound on the waker function. This resulted in a use-after-free if Waker::wake() is called after original data had been dropped.

The flaw was corrected by adding 'static lifetime bound to the data waker takes.

Пакеты

Наименование

futures-task

rust
Затронутые версииВерсия исправления

>= 0.2.1, < 0.3.6

0.3.6

EPSS

Процентиль: 17%
0.00055
Низкий

7.8 High

CVSS3

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 5 лет назад

An issue was discovered in the futures-task crate before 0.3.6 for Rust. futures_task::waker may cause a use-after-free in a non-static type situation.

CVSS3: 7.8
nvd
около 5 лет назад

An issue was discovered in the futures-task crate before 0.3.6 for Rust. futures_task::waker may cause a use-after-free in a non-static type situation.

CVSS3: 7.8
debian
около 5 лет назад

An issue was discovered in the futures-task crate before 0.3.6 for Rus ...

EPSS

Процентиль: 17%
0.00055
Низкий

7.8 High

CVSS3

Дефекты

CWE-416