PT-2026-76522 · Crates.Io · Dcrypt-Api
Published
2026-08-09
·
Updated
2026-08-09
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
All published versions of
dcrypt-api before 2.0.0 exposed safe
ErrorRegistry operations that could trigger undefined behavior when the
default std feature was enabled.Stored
Box<E> values were erased to raw pointers and later deallocated as
Box<()>. The get error<E> operation also performed an unchecked cast to a
caller-selected type. Finally, concurrent replacement or clearing could free a
value while another thread cloned it. Ordinary safe Rust could therefore cause
mismatched deallocation, type confusion, and use-after-free. Crates that
re-exported this API are affected transitively.Version 2.0.0 replaces the raw pointers with owned
Box<dyn Any + Send> values
behind a mutex, performs checked downcasts, and uses a mutation generation so
concurrent stores and clears win safely. There is no reliable workaround while
calling the affected registry API. Upgrade to 2.0.0 or later and avoid
process-global error state where possible. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dcrypt-Api