stackabletech / stackabletech/stackablectl
RUSTSEC-2026-0221: `event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`
Nobody has claimed this yet.
- Dominant language
- Rust
- Stars
- 10
- Forks
- 5
- Avg merge
- 4h 41m
- Merged PRs (30d)
- 4
Description
event-listenerallows!Sendtags to cross thread boundaries viaStackSlot
| Details | |
|---|---|
| Status | unsound |
| Package | event-listener |
| Version | 5.4.1 |
| URL | https://github.com/smol-rs/event-listener/pull/163 |
| Date | 2026-07-13 |
Affected versions of event-listener unconditionally implement Send and
Sync for StackSlot<'_, T>, the stack-allocated listener type created
by the listener! macro.
This allows a !Send tag type set via Event::with_tag to be moved to
another thread and accessed via StackSlot::wait, causing a data race in safe
code.
See advisory page for additional details.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reading the advisory details and checking how event-listener 5.4.1 enters this repository. Identify the dependency manifest or lockfile involved and confirm the affected version's usage. Done means the unsound dependency is addressed and the repository no longer resolves the affected version.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust
- Domain
- security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100