CVE-2018-25008

CWE-6626 documents6 sources
Severity
5.9MEDIUM
EPSS
0.2%
top 56.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 14
Latest updateMay 24

Description

In the standard library in Rust before 1.29.0, there is weak synchronization in the Arc::get_mut method. This synchronization issue can be lead to memory safety issues through race conditions.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages2 packages

NVDrust-lang/rust< 1.29.0
Debianrustc< 1.29.0+dfsg1-1+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-prm6-42x6-pwfm: In the standard library in Rust before 12022-05-24
CVEList
CVE-2018-25008: In the standard library in Rust before 12021-04-14
OSV
CVE-2018-25008: In the standard library in Rust before 12021-04-14

📋Vendor Advisories

2
Red Hat
rust: weak synchronization in the Arc::get_mut method2018-06-25
Debian
CVE-2018-25008: rustc - In the standard library in Rust before 1.29.0, there is weak synchronization in ...2018
CVE-2018-25008 (MEDIUM CVSS 5.9) | In the standard library in Rust bef | cvebase.io