{"id":"GHSA-48m6-wm5p-rr6h","summary":"Insufficient covariance check makes self_cell unsound","details":"All public versions prior to `1.02` used an insufficient check to ensure that users correctly marked the dependent type as either `covariant` or `not_covariant`. This allowed users to mark a dependent as covariant even though its type was not covariant but invariant, for certain invariant types involving trait object lifetimes. One example for such a dependent type is `type Dependent\u003c'a\u003e = RefCell\u003cBox\u003cdyn fmt::Display + 'a\u003e\u003e`. Such a type allowed unsound usage in purely safe user code that leads to undefined behavior. The patched versions now produce a compile time error if such a type is marked as `covariant`.","aliases":["RUSTSEC-2023-0070"],"modified":"2024-02-10T16:26:48.155893Z","published":"2023-11-14T18:32:20Z","database_specific":{"github_reviewed_at":"2023-11-14T18:32:20Z","nvd_published_at":null,"cwe_ids":[],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/Voultapher/self_cell/issues/49"},{"type":"PACKAGE","url":"https://github.com/Voultapher/self_cell"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2023-0070.html"}],"affected":[{"package":{"name":"self_cell","ecosystem":"crates.io","purl":"pkg:cargo/self_cell"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.10.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-48m6-wm5p-rr6h/GHSA-48m6-wm5p-rr6h.json"}},{"package":{"name":"self_cell","ecosystem":"crates.io","purl":"pkg:cargo/self_cell"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.0.0"},{"fixed":"1.0.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-48m6-wm5p-rr6h/GHSA-48m6-wm5p-rr6h.json"}}],"schema_version":"1.9.0"}