First published: Thu Dec 31 2020(Updated: )
An issue was discovered in the futures-task crate before 0.3.6 for Rust. futures_task::waker may cause a use-after-free in a non-static type situation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Rust-lang Futures-task | <0.3.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2020-35906.
The title of this vulnerability is 'An issue was discovered in the futures-task crate before 0.3.6 for Rust. futures_task::waker may cause a use-after-free in a non-static type situation.'
The severity of CVE-2020-35906 is high with a CVSS score of 7.8.
The Rust-lang Futures-task crate versions up to exclusive 0.3.6 are affected by CVE-2020-35906.
To fix the vulnerability CVE-2020-35906, update the affected software to a version beyond 0.3.6.