In crossbeam-channel rust crate, the internal `Channel` type's `Drop` method has a race condition which could, in some circumstances, lead to a double-free that could result in memory corruption.
History

Fri, 16 May 2025 02:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 15 May 2025 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat directory Server
Redhat enterprise Linux
Redhat openshift
Redhat openshift Ai
Redhat satellite
Redhat trusted Artifact Signer
Redhat trusted Profile Analyzer
CPEs cpe:/a:redhat:directory_server:11
cpe:/a:redhat:directory_server:12
cpe:/a:redhat:openshift:4
cpe:/a:redhat:openshift_ai
cpe:/a:redhat:satellite:6
cpe:/a:redhat:trusted_artifact_signer:1
cpe:/a:redhat:trusted_profile_analyzer:2
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat directory Server
Redhat enterprise Linux
Redhat openshift
Redhat openshift Ai
Redhat satellite
Redhat trusted Artifact Signer
Redhat trusted Profile Analyzer

Wed, 14 May 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 13 May 2025 22:00:00 +0000

Type Values Removed Values Added
Description In crossbeam-channel rust crate, the internal `Channel` type's `Drop` method has a race condition which could, in some circumstances, lead to a double-free that could result in memory corruption.
Title Crossbeam-channel: crossbeam-channel vulnerable to double free on drop
Weaknesses CWE-415
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-05-15T12:19:34.739Z

Reserved: 2025-05-12T12:06:47.274Z

Link: CVE-2025-4574

cve-icon Vulnrichment

Updated: 2025-05-14T13:30:50.043Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-13T22:15:25.143

Modified: 2025-05-16T14:43:56.797

Link: CVE-2025-4574

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-04-10T14:30:39Z

Links: CVE-2025-4574 - Bugzilla