{"ecosystem":"cargo","package":"chrono","version":null,"bugs":[{"id":893,"ecosystem":"cargo","package_name":"chrono","affected_version":"0.0.0-0","fixed_version":"0.4.20","bug_id":"osv:RUSTSEC-2020-0159","title":"Potential segfault in `localtime_r` invocations","description":"### Impact\n\nUnix-like operating systems may segfault due to dereferencing a dangling pointer in specific circumstances. This requires an environment variable to be set in a different thread than the affected functions. This may occur without the user's knowledge, notably in a third-party library.\n\n### Workarounds\n\nNo workarounds are known.\n\n### References\n\n- [time-rs/time#293](https://github.com/time-rs/time/issues/293)","severity":"medium","status":"fixed","source":"osv","source_url":"https://crates.io/crates/chrono","labels":[],"created_at":"2026-04-19 04:32:06.122921+00:00","updated_at":"2026-04-19 04:32:06.122921+00:00"}],"total":1,"_cache":"hit"}