PT-2021-16832 · Lazy-Init · Lazy-Init

Published

2021-01-17

·

Updated

2021-08-25

·

CVE-2021-25901

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions lazy-init crate through 2021-01-17
Description The issue is related to the lazy-init crate for Rust, where lazy lacks a Send bound, leading to a data race. This allows causing data races in safe code.
Recommendations For versions of the lazy-init crate through 2021-01-17, update to the next release to fix the issue.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-25901
GHSA-W47J-HQPF-QW9W
RUSTSEC-2021-0004

Affected Products

Lazy-Init