First published: Thu Dec 31 2020(Updated: )
An issue was discovered in the futures-task crate before 0.3.5 for Rust. futures_task::noop_waker_ref allows a NULL pointer dereference.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Rust-lang Futures-task | <0.3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35907 is an issue discovered in the futures-task crate before version 0.3.5 for Rust.
CVE-2020-35907 has a severity rating of 5.5 (medium).
The affected software is the futures-task crate for Rust with versions up to 0.3.5.
CVE-2020-35907 is classified as CWE-476, which is a NULL pointer dereference vulnerability.
Yes, the fix for CVE-2020-35907 is to update the futures-task crate to version 0.3.5 or newer.