Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rw2c-c256-3r53

Опубликовано: 25 авг. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Data races in hashconsing

Affected versions of hashconsing implements Send/Sync for its HConsed type without restricting it to Sendable types and Syncable types. This allows non-Sync types such as Cell to be shared across threads leading to undefined behavior and memory corruption in concurrent programs.

Пакеты

Наименование

hashconsing

rust
Затронутые версииВерсия исправления

< 1.1.0

1.1.0

EPSS

Процентиль: 59%
0.00389
Низкий

7.5 High

CVSS3

Дефекты

CWE-662
CWE-787

Связанные уязвимости

CVSS3: 7.5
nvd
около 5 лет назад

An issue was discovered in the hashconsing crate before 1.1.0 for Rust. Because HConsed does not have bounds on its Send trait or Sync trait, memory corruption can occur.

EPSS

Процентиль: 59%
0.00389
Низкий

7.5 High

CVSS3

Дефекты

CWE-662
CWE-787