Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-4574

Опубликовано: 10 апр. 2025
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

In crossbeam-channel rust crate, the internal Channel type's Drop method has a race condition which could, in some circumstances, lead to a double-free that could result in memory corruption.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Directory Server 11redhat-ds:11/389-ds-baseNot affected
Red Hat Directory Server 12redhat-ds:12/389-ds-baseNot affected
Red Hat Enterprise Linux 10389-ds-baseFix deferred
Red Hat Enterprise Linux 10firefoxFix deferred
Red Hat Enterprise Linux 10gjsNot affected
Red Hat Enterprise Linux 10rustFix deferred
Red Hat Enterprise Linux 10rust-afterburnFix deferred
Red Hat Enterprise Linux 10thunderbirdFix deferred
Red Hat Enterprise Linux 10trustee-guest-componentsFix deferred
Red Hat Enterprise Linux 7firefoxFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-415
https://bugzilla.redhat.com/show_bug.cgi?id=2358890crossbeam-channel: crossbeam-channel Vulnerable to Double Free on Drop

EPSS

Процентиль: 17%
0.00055
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
3 месяца назад

In crossbeam-channel rust crate, the internal `Channel` type's `Drop` method has a race condition which could, in some circumstances, lead to a double-free that could result in memory corruption.

CVSS3: 6.5
nvd
3 месяца назад

In crossbeam-channel rust crate, the internal `Channel` type's `Drop` method has a race condition which could, in some circumstances, lead to a double-free that could result in memory corruption.

CVSS3: 6.5
msrc
около 1 месяца назад

Описание отсутствует

CVSS3: 6.5
debian
3 месяца назад

In crossbeam-channel rust crate, the internal `Channel` type's `Drop` ...

github
4 месяца назад

crossbeam-channel Vulnerable to Double Free on Drop

EPSS

Процентиль: 17%
0.00055
Низкий

6.5 Medium

CVSS3