All published versions of dcrypt-api before 2.0.0 exposed safe
ErrorRegistry operations that could trigger undefined behavior when the
default std feature was enabled.
Stored Box<E> values were erased to raw pointers and later deallocated as
Box<()>. The get_error<E> operation also performed an unchecked cast to a
caller-selected type. Finally, concurrent replacement or clearing could free a
value while another thread cloned it. Ordinary safe Rust could therefore cause
mismatched deallocation, type confusion, and use-after-free. Crates that
re-exported this API are affected transitively.
Version 2.0.0 replaces the raw pointers with owned Box<dyn Any + Send> values
behind a mutex, performs checked downcasts, and uses a mutation generation so
concurrent stores and clears win safely. There is no reliable workaround while
calling the affected registry API. Upgrade to 2.0.0 or later and avoid
process-global error state where possible.
{
"license": "CC0-1.0"
}