Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-4574

Опубликовано: 13 мая 2025
Источник: debian

Описание

In crossbeam-channel rust crate, the internal `Channel` type's `Drop` method has a race condition which could, in some circumstances, lead to a double-free that could result in memory corruption.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rust-crossbeam-channelfixed0.5.15-1package
rust-crossbeam-channelnot-affectedbookwormpackage
rust-crossbeam-channelnot-affectedbullseyepackage

Примечания

  • https://rustsec.org/advisories/RUSTSEC-2025-0024.html

  • https://github.com/crossbeam-rs/crossbeam/pull/1187

  • Fixed by: https://github.com/crossbeam-rs/crossbeam/commit/6ec74ecae896df5fc239518b45a1bfd258c9db68 (crossbeam-channel-0.5.15)

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 месяца назад

In crossbeam-channel rust crate, the internal `Channel` type's `Drop` method has a race condition which could, in some circumstances, lead to a double-free that could result in memory corruption.

CVSS3: 6.5
redhat
2 месяца назад

In crossbeam-channel rust crate, the internal `Channel` type's `Drop` method has a race condition which could, in some circumstances, lead to a double-free that could result in memory corruption.

CVSS3: 6.5
nvd
около 1 месяца назад

In crossbeam-channel rust crate, the internal `Channel` type's `Drop` method has a race condition which could, in some circumstances, lead to a double-free that could result in memory corruption.

github
2 месяца назад

crossbeam-channel Vulnerable to Double Free on Drop

suse-cvrf
около 1 месяца назад

Security update for python-maturin