fragile is vulnerable to Memory Corruption
50
Medium Risk
Wrapping a future or stream whose state is !Unpin in Fragile or Sticky and polling it previously still let the wrapper count as Unpin while keeping the wrapped value stored inline, so the whole wrapper, including the pinned value, could still be moved by ordinary safe code such as into_inner or a container swap after a pinned reference had already been handed out. Moving a !Unpin value after it has been pinned breaks the pinning guarantee its Future implementation relies on, so self-referential pointers it holds become stale, which can corrupt memory on the next poll. The fix moves the value to stable, pinned heap storage before the first poll and makes the wrapper Unpin only when the wrapped value is, so a pinned !Unpin value can no longer be moved out.
You are affected if you are using a version that falls within the vulnerable range and you wrap a !Unpin future or stream in Fragile or Sticky using the crate's future/stream support.
fragile is vulnerable to Memory Corruption in versions 2.1.0 - 2.1.0.
Upgrade the fragile library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.