cbcvebase.
CVE-2021-32810
published 2021-08-02

CVE-2021-32810: crossbeam-deque is a package of work-stealing deques for building task schedulers when programming in Rust. In versions prior to 0.7.4 and 0.8.0, the result of…

PriorityP350critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.92%
77.4th percentile
crossbeam-deque is a package of work-stealing deques for building task schedulers when programming in Rust. In versions prior to 0.7.4 and 0.8.0, the result of the race condition is that one or more tasks in the worker queue can be popped twice instead of other tasks that are forgotten and never popped. If tasks are allocated on the heap, this can cause double free and a memory leak. If not, this still can cause a logical bug. Crates using `Stealer::steal`, `Stealer::steal_batch`, or `Stealer::steal_batch_and_pop` are affected by this issue. This has been fixed in crossbeam-deque 0.8.1 and 0.7.4.

Affected

10 ranges
VendorProductVersion rangeFixed in
crossbeam-rscrossbeam< 0.7.40.7.4
crossbeam-rscrossbeam
crossbeam_projectcrossbeam< 0.7.40.7.4
crossbeam_projectcrossbeam>= 0.8.0 < 0.8.10.8.1
debianfirefox< firefox 93.0-1 (sid)firefox 93.0-1 (sid)
debianfirefox-esr< firefox 93.0-1 (sid)firefox 93.0-1 (sid)
debianrust-crossbeam-deque< firefox 93.0-1 (sid)firefox 93.0-1 (sid)
debianthunderbird< firefox 93.0-1 (sid)firefox 93.0-1 (sid)
fedoraprojectfedora
mozillafirefox

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.