{"id":"CVE-2020-36444","aliases":["RUSTSEC-2020-0124"],"url":"https://o3.security/vulnerability/CVE-2020-36444","summary":"Data races in async-coap","details":"An issue was discovered in the async-coap crate through 2020-12-08 for Rust. \nAffected versions of this crate implement Send/Sync for `ArcGuard<RC, T>` with no trait bounds on `RC`. This allows users to send `RC: !Send` to other threads and also allows users to concurrently access `Rc: !Sync` from multiple threads.\n\nThis can result in memory corruption from data race or other undefined behavior caused by sending `T: !Send` to other threads (e.g. dropping `MutexGuard<T>` in another thread that didn't lock its mutex).\n","published":"2021-08-25T20:59:11Z","modified":"2023-11-08T04:03:45.205946Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"async-coap","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-36444"},{"type":"WEB","url":"https://github.com/google/rust-async-coap/issues/33"},{"type":"PACKAGE","url":"https://github.com/google/rust-async-coap"},{"type":"WEB","url":"https://raw.githubusercontent.com/rustsec/advisory-db/main/crates/async-coap/RUSTSEC-2020-0124.md"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2020-0124.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T04:03:45.205946Z"}}