Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🦀 crates.io
Not in CISA KEV

GHSA-w59h-378f-2frm threadalone

GHSA-w59h-378f-2frm is a security vulnerability in threadalone. A fix is available for threadalone — see the affected versions and patch details below.

Unsound sending of non-Send types across threads in threadalone

Also known asRUSTSEC-2024-0005
Published
Jan 23, 2024
Updated
Feb 10, 2024
Affected
1 pkg
Patched
1 / 1
Exploits
None indexed
Exploitation data as of Feb 10, 2024 · OSV.dev, FIRST.org (EPSS)

Real-World Exposure

1 pkg affected
🦀threadalone

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects crates.io packages — download data is not available via public APIs for these ecosystems.

Description

Affected versions can run the Drop impl of a non-Send type on a different thread than it was created on.

The flaw occurs when a stderr write performed by the threadalone crate fails, for example because stderr is redirected to a location on a filesystem that is full, or because stderr is a pipe that has been closed by the reader.

Dropping a non-Send type on the wrong thread is unsound. If used with a type such as a pthread-based MutexGuard, the consequence is undefined behavior. If used with Rc, there would be a data race on the reference count, which is likewise undefined behavior.

Affected Packages

1 total 1 fixed
EcosystemPackageVulnerable rangeFix
🦀crates.iothreadaloneall versions0.2.1cargo update -p threadalone --precise 0.2.1

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for threadalone, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update threadalone to 0.2.1 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-w59h-378f-2frm is resolved across your whole dependency graph.

  3. Workarounds

    If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.

  4. How O3 protects you

    O3 Security's impact-aware SCA analyses which vulnerable code paths your application actually calls, so a match like GHSA-w59h-378f-2frm can be triaged on real exposure rather than presence alone.

Tailored to GHSA-w59h-378f-2frm. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.

Frequently Asked Questions

Affected versions can run the `Drop` impl of a non-Send type on a different thread than it was created on. The flaw occurs when a stderr write performed by the `threadalone` crate fails, for example because stderr is redirected to a location on a filesystem that is full, or because stderr is a pipe that has been closed by the reader. Dropping a non-Send type on the wrong thread is unsound. If used with a type such as a pthread-based `MutexGuard`, [the consequence is undefined behavior][mutexguard]. If used with `Rc`, there would be a data race on the reference count, which is likewise undefi
O3 Security · Impact-Aware SCA

Is GHSA-w59h-378f-2frm in your dependencies?

O3 Security finds GHSA-w59h-378f-2frm across crates.io dependencies, including transitive ones, and its impact-aware SCA ranks findings by whether your code actually calls the vulnerable path.

GHSA-w59h-378f-2frm: threadalone | O3 Security