Headline
GHSA-cqpr-pcm7-m3jc: Potential segfault in `localtime_r` invocations
Impact
Unix-like operating systems may segfault due to dereferencing a dangling pointer in specific circumstances. This requires an environment variable to be set in a different thread than the affected functions. This may occur without the user’s knowledge, notably in a third-party library.
Workarounds
No workarounds are known.
References
Potential segfault in `localtime_r` invocations
Moderate severity GitHub Reviewed Published Jun 16, 2022 • Updated Jun 16, 2022