{"id":"CVE-2020-36462","aliases":["GHSA-vp6r-mrq9-8f4h","RUSTSEC-2020-0142"],"url":"https://o3.security/vulnerability/CVE-2020-36462","summary":"Duplicate Advisory: Data races on syncpool","details":"## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-vp6r-mrq9-8f4h. This link is maintained to preserve external references.\n\n## Original Description\nAffected versions of this crate unconditionally implements `Send` for `Bucket2`. This allows sending non-Send types to other threads.\n\nThis can lead to data races when non Send types like `Cell<T>` or `Rc<T>` are contained inside `Bucket2` and sent across thread boundaries. The data races can potentially lead to memory corruption (as demonstrated in the PoC from the original report issue).\n\nThe flaw was corrected in commit `15b2828` by adding a `T: Send` bound to the `Send` impl of `Bucket2<T>`.","published":"2021-08-25T21:00:28Z","modified":"2026-02-03T03:07:50.215416Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"crates.io","name":"syncpool","fixedVersion":"0.1.6"}],"fix":{"url":"https://github.com/Chopinsky/byte_buffer/commit/15b282877d1e576de2b337d8162bbf43ed1a0f2d","label":"Chopinsky/byte_buffer@15b2828"},"references":[{"type":"WEB","url":"https://github.com/Chopinsky/byte_buffer/issues/2"},{"type":"WEB","url":"https://github.com/Chopinsky/byte_buffer/commit/15b282877d1e576de2b337d8162bbf43ed1a0f2d"},{"type":"PACKAGE","url":"https://github.com/Chopinsky/byte_buffer/tree/master/syncpool"},{"type":"WEB","url":"https://github.com/RustSec/advisory-db/blob/main/crates/syncpool/RUSTSEC-2020-0142.md"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2020-0142.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-02-03T03:07:50.215416Z"}}