CVE-2017-20004

CWE-362Race Condition6 documents6 sources
Severity
5.9MEDIUM
EPSS
0.2%
top 52.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 14
Latest updateMay 24

Description

In the standard library in Rust before 1.19.0, there is a synchronization problem in the MutexGuard object. MutexGuards can be used across threads with any types, allowing for memory safety issues through race conditions.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages2 packages

NVDrust-lang/rust< 1.19.0
Debianrustc< 1.19.0+dfsg3-2+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-9pmw-f3q3-5rcf: In the standard library in Rust before 12022-05-24
OSV
CVE-2017-20004: In the standard library in Rust before 12021-04-14
CVEList
CVE-2017-20004: In the standard library in Rust before 12021-04-14

📋Vendor Advisories

2
Red Hat
rust: synchronization problem in the MutexGuard object2017-04-29
Debian
CVE-2017-20004: rustc - In the standard library in Rust before 1.19.0, there is a synchronization proble...2017
CVE-2017-20004 (MEDIUM CVSS 5.9) | In the standard library in Rust bef | cvebase.io