[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2021-32810Date: (C)2021-08-03   (M)2024-03-27


crossbeam-deque is a package of work-stealing deques for building task schedulers when programming in Rust. In versions prior to 0.7.4 and 0.8.0, the result of the race condition is that one or more tasks in the worker queue can be popped twice instead of other tasks that are forgotten and never popped. If tasks are allocated on the heap, this can cause double free and a memory leak. If not, this still can cause a logical bug. Crates using `Stealer::steal`, `Stealer::steal_batch`, or `Stealer::steal_batch_and_pop` are affected by this issue. This has been fixed in crossbeam-deque 0.8.1 and 0.7.4.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 9.8CVSS Score : 6.8
Exploit Score: 3.9Exploit Score: 8.6
Impact Score: 5.9Impact Score: 6.4
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: MEDIUM
Privileges Required: NONEAuthentication: NONE
User Interaction: NONEConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: PARTIAL
Confidentiality: HIGHAvailability: PARTIAL
Integrity: HIGH 
Availability: HIGH 
  
Reference:
FEDORA-2021-0f82e9d6d5
FEDORA-2021-2db6c84087
FEDORA-2021-32c9adf002
FEDORA-2021-3cf88e44b4
FEDORA-2021-537541ceae
FEDORA-2021-5e99655cca
FEDORA-2021-60f0e1bb35
FEDORA-2021-67d6c34e5b
FEDORA-2021-79ce3cb64a
FEDORA-2021-9dc0bd0072
FEDORA-2021-a5161737c3
FEDORA-2021-af2eb94426
FEDORA-2021-e37a366b00
FEDORA-2021-e5ec6d55bf
https://github.com/crossbeam-rs/crossbeam/security/advisories/GHSA-pqqp-xmhj-wgcw

CWE    1
CWE-362
OVAL    44
oval:org.secpod.oval:def:506352
oval:org.secpod.oval:def:506359
oval:org.secpod.oval:def:506382
oval:org.secpod.oval:def:506381
...

© SecPod Technologies