-
Notifications
You must be signed in to change notification settings - Fork 364
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Crossbeam AtomicCell<*64> Soundness #1203
Comments
GHSA are on CC-BY-4.0 and RustSec is on Public Domain Would you like to send a PR ? Just please ensure the contents are from CVE source (can still link to GHSA though) Or I can do later - Cheers Stats: Crate: crossbeam-utils Total all versions 75,264,545 downloads - ~120k a day 0.8.7 - 7k downloads a day - 2.8M total all time Affected is all < 0.8.7 0.8 release stream is yanked Semver 0.7 seems to have got stuck on people's manifests 0.7.2 stuck in Time to parse ecosystem manifests who are the biggest 0.7 users and try to get big downstreamers to semver up their manifests |
The maintainer has released the advisory on Public domain I will sketch a PR |
crossbeam released a security update for 0.8.7. It would be good to have this in rustsec.
GHSA-qc84-gqf4-9926
The text was updated successfully, but these errors were encountered: