Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-4574

Опубликовано: 13 мая 2025
Источник: debian
EPSS Низкий

Описание

In crossbeam-channel rust crate, the internal `Channel` type's `Drop` method has a race condition which could, in some circumstances, lead to a double-free that could result in memory corruption.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rust-crossbeam-channelfixed0.5.15-1package
rust-crossbeam-channelnot-affectedbookwormpackage
rust-crossbeam-channelnot-affectedbullseyepackage

Примечания

  • https://rustsec.org/advisories/RUSTSEC-2025-0024.html

  • https://github.com/crossbeam-rs/crossbeam/pull/1187

  • Fixed by: https://github.com/crossbeam-rs/crossbeam/commit/6ec74ecae896df5fc239518b45a1bfd258c9db68 (crossbeam-channel-0.5.15)

EPSS

Процентиль: 19%
0.0006
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
6 месяцев назад

In crossbeam-channel rust crate, the internal `Channel` type's `Drop` method has a race condition which could, in some circumstances, lead to a double-free that could result in memory corruption.

CVSS3: 6.5
redhat
7 месяцев назад

In crossbeam-channel rust crate, the internal `Channel` type's `Drop` method has a race condition which could, in some circumstances, lead to a double-free that could result in memory corruption.

CVSS3: 6.5
nvd
6 месяцев назад

In crossbeam-channel rust crate, the internal `Channel` type's `Drop` method has a race condition which could, in some circumstances, lead to a double-free that could result in memory corruption.

CVSS3: 4.8
msrc
4 месяца назад

Crossbeam-channel: crossbeam-channel vulnerable to double free on drop

github
7 месяцев назад

crossbeam-channel Vulnerable to Double Free on Drop

EPSS

Процентиль: 19%
0.0006
Низкий
Уязвимость CVE-2025-4574