Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fg7r-2g4j-5cgr

Опубликовано: 06 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Race Condition in tokio

If a tokio::sync::oneshot channel is closed (via the oneshot::Receiver::close method), a data race may occur if the oneshot::Sender::send method is called while the corresponding oneshot::Receiver is awaited or calling try_recv.

When these methods are called concurrently on a closed channel, the two halves of the channel can concurrently access a shared memory location, resulting in a data race. This has been observed to cause memory corruption.

Note that the race only occurs when both halves of the channel are used after the Receiver half has called close. Code where close is not used, or where the Receiver is not awaited and try_recv is not called after calling close, is not affected.

Пакеты

Наименование

tokio

rust
Затронутые версииВерсия исправления

>= 0.1.14, < 1.8.4

1.8.4

Наименование

tokio

rust
Затронутые версииВерсия исправления

>= 1.9.0, < 1.13.1

1.13.1

EPSS

Процентиль: 41%
0.00194
Низкий

8.1 High

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 4 лет назад

An issue was discovered in the tokio crate before 1.8.4, and 1.9.x through 1.13.x before 1.13.1, for Rust. In certain circumstances involving a closed oneshot channel, there is a data race and memory corruption.

CVSS3: 7.3
redhat
около 4 лет назад

An issue was discovered in the tokio crate before 1.8.4, and 1.9.x through 1.13.x before 1.13.1, for Rust. In certain circumstances involving a closed oneshot channel, there is a data race and memory corruption.

CVSS3: 8.1
nvd
около 4 лет назад

An issue was discovered in the tokio crate before 1.8.4, and 1.9.x through 1.13.x before 1.13.1, for Rust. In certain circumstances involving a closed oneshot channel, there is a data race and memory corruption.

CVSS3: 8.1
debian
около 4 лет назад

An issue was discovered in the tokio crate before 1.8.4, and 1.9.x thr ...

suse-cvrf
около 3 лет назад

Security update for 389-ds

EPSS

Процентиль: 41%
0.00194
Низкий

8.1 High

CVSS3

Дефекты

CWE-362