CVE-2018-25008
published 2021-04-14CVE-2018-25008: In the standard library in Rust before 1.29.0, there is weak synchronization in the Arc::get_mut method. This synchronization issue can be lead to memory…
PriorityP427medium5.9CVSS 3.1
AVNACHPRNUINSUCNIHAN
EPSS
1.05%
60.4th percentile
In the standard library in Rust before 1.29.0, there is weak synchronization in the Arc::get_mut method. This synchronization issue can be lead to memory safety issues through race conditions.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rustc | < rustc 1.29.0+dfsg1-1 (bookworm) | rustc 1.29.0+dfsg1-1 (bookworm) |
| rust-lang | rust | < 1.29.0 | 1.29.0 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rust: weak synchronization in the Arc::get_mut method
vendor_redhat·2018-06-25·CVSS 5.9
CVE-2018-25008 [MEDIUM] CWE-662 rust: weak synchronization in the Arc::get_mut method
rust: weak synchronization in the Arc::get_mut method
In the standard library in Rust before 1.29.0, there is weak synchronization in the Arc::get_mut method. This synchronization issue can be lead to memory safety issues through race conditions.
Package: rust-toolset:rhel8/rust (Red Hat Enterprise Linux 8) - Not affected
Package: rust (Red Hat Enterprise Linux 9) - Not affected
Debian
CVE-2018-25008: rustc - In the standard library in Rust before 1.29.0, there is weak synchronization in ...
vendor_debian·2018·CVSS 5.9
CVE-2018-25008 [MEDIUM] CVE-2018-25008: rustc - In the standard library in Rust before 1.29.0, there is weak synchronization in ...
In the standard library in Rust before 1.29.0, there is weak synchronization in the Arc::get_mut method. This synchronization issue can be lead to memory safety issues through race conditions.
Scope: local
bookworm: resolved (fixed in 1.29.0+dfsg1-1)
bullseye: resolved (fixed in 1.29.0+dfsg1-1)
forky: resolved (fixed in 1.29.0+dfsg1-1)
sid: resolved (fixed in 1.29.0+dfsg1-1)
trixie: resolved (fixed in 1.29.0+dfsg1-1)
GHSA
GHSA-prm6-42x6-pwfm: In the standard library in Rust before 1
ghsa_unreviewed·2022-05-24
CVE-2018-25008 [MEDIUM] CWE-662 GHSA-prm6-42x6-pwfm: In the standard library in Rust before 1
In the standard library in Rust before 1.29.0, there is weak synchronization in the Arc::get_mut method. This synchronization issue can be lead to memory safety issues through race conditions.
OSV
CVE-2018-25008: In the standard library in Rust before 1
osv·2021-04-14·CVSS 5.9
CVE-2018-25008 [MEDIUM] CVE-2018-25008: In the standard library in Rust before 1
In the standard library in Rust before 1.29.0, there is weak synchronization in the Arc::get_mut method. This synchronization issue can be lead to memory safety issues through race conditions.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-04-14
Published