{"id":"GHSA-7mg7-m5c3-3hqj","summary":"Data races in unicycle","details":"Affected versions of this crate unconditionally implemented `Send` & `Sync` for types `PinSlab\u003cT\u003e` & `Unordered\u003cT, S\u003e`. This allows sending non-Send types to other threads and concurrently accessing non-Sync types from multiple threads.\n\nThis can result in a data race & memory corruption when types that provide internal mutability without synchronization are contained within `PinSlab\u003cT\u003e` or `Unordered\u003cT, S\u003e` and accessed concurrently from multiple threads.\n\nThe flaw was corrected in commits 92f40b4 & 6a6c367 by adding trait bound `T: Send` to `Send` impls for `PinSlab\u003cT\u003e` & `Unordered\u003cT, S\u003e` and adding `T: Sync` to `Sync` impls for `PinSlab\u003cT\u003e` & `Unordered\u003cT, S\u003e`.\n","modified":"2021-08-24T17:47:15Z","published":"2021-08-25T21:00:39Z","withdrawn":"2021-08-24T17:47:15Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2021-08-05T21:14:52Z","nvd_published_at":null,"cwe_ids":["CWE-362"]},"references":[{"type":"WEB","url":"https://github.com/udoprog/unicycle/issues/8"},{"type":"WEB","url":"https://github.com/udoprog/unicycle/commit/6a6c367a0c25f86f998fa315ea90c328f685b194"},{"type":"WEB","url":"https://github.com/udoprog/unicycle/commit/92f40b4a2c671553dfa96feacff0265206c44ce5"},{"type":"PACKAGE","url":"https://github.com/udoprog/unicycle"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2020-0116.html"}],"affected":[{"package":{"name":"unicycle","ecosystem":"crates.io","purl":"pkg:cargo/unicycle"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.7.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/08/GHSA-7mg7-m5c3-3hqj/GHSA-7mg7-m5c3-3hqj.json"}}],"schema_version":"1.9.0"}