<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 02:47:10 +0000</lastBuildDate>
    <item>
      <title>CLEANSTART-2025-KZ08626 — Security fix for ghsa-pg9f-39pc-qf8g applied in: ztunnel-fips 1.25.5-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2025-kz08626</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: ztunnel-fips&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the ztunnel-fips package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: ztunnel-fips&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the ztunnel-fips package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2025-kz08626</guid>
    </item>
    <item>
      <title>CVE-2025-4574 — Crossbeam-channel: crossbeam-channel vulnerable to double free on drop</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-4574</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crossbeam-channel, Red Hat Directory Server 11, Red Hat Directory Server 12, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat Satellite 6 and 2 more&lt;/p&gt;
&lt;p&gt;In crossbeam-channel rust crate, the internal `Channel` type&amp;#39;s `Drop` method has a race condition which could, in some circumstances, lead to a double-free that could result in memory corruption.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crossbeam-channel, Red Hat Directory Server 11, Red Hat Directory Server 12, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat Satellite 6 and 2 more&lt;/p&gt;
&lt;p&gt;In crossbeam-channel rust crate, the internal `Channel` type&amp;#39;s `Drop` method has a race condition which could, in some circumstances, lead to a double-free that could result in memory corruption.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-4574</guid>
    </item>
    <item>
      <title>RUSTSEC-2025-0024 — crossbeam-channel: double free on Drop</title>
      <link>https://cve.radiocsirt.org/vuln/rustsec-2025-0024</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: crossbeam-channel&lt;/p&gt;
&lt;p&gt;The internal `Channel` type&amp;#39;s `Drop` method has a race
which could, in some circumstances, lead to a double-free.
This could result in memory corruption.&lt;/p&gt;
&lt;p&gt;Quoting from the
[upstream description in merge request \#1187](https://github.com/crossbeam-rs/crossbeam/pull/1187#issue-2980761131):&lt;/p&gt;
&lt;p&gt;&amp;gt; The problem lies in the fact that `dicard_all_messages` contained two paths that could lead to `head.block` being read but only one of them would swap the value. This meant that `dicard_all_messages` could end up observing a non-null block pointer (and therefore attempting to free it) without setting `head.block` to null. This would then lead to `Channel::drop` making a second attempt at dropping the same pointer.&lt;/p&gt;
&lt;p&gt;The bug was introduced while fixing a memory leak, in
upstream [MR \#1084](https://github.com/crossbeam-rs/crossbeam/pull/1084),
first published in 0.5.12.&lt;/p&gt;
&lt;p&gt;The fix is in
upstream [MR \#1187](https://github.com/crossbeam-rs/crossbeam/pull/1187)
and has been published in 0.5.15&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: crossbeam-channel&lt;/p&gt;
&lt;p&gt;The internal `Channel` type&amp;#39;s `Drop` method has a race
which could, in some circumstances, lead to a double-free.
This could result in memory corruption.&lt;/p&gt;
&lt;p&gt;Quoting from the
[upstream description in merge request \#1187](https://github.com/crossbeam-rs/crossbeam/pull/1187#issue-2980761131):&lt;/p&gt;
&lt;p&gt;&amp;gt; The problem lies in the fact that `dicard_all_messages` contained two paths that could lead to `head.block` being read but only one of them would swap the value. This meant that `dicard_all_messages` could end up observing a non-null block pointer (and therefore attempting to free it) without setting `head.block` to null. This would then lead to `Channel::drop` making a second attempt at dropping the same pointer.&lt;/p&gt;
&lt;p&gt;The bug was introduced while fixing a memory leak, in
upstream [MR \#1084](https://github.com/crossbeam-rs/crossbeam/pull/1084),
first published in 0.5.12.&lt;/p&gt;
&lt;p&gt;The fix is in
upstream [MR \#1187](https://github.com/crossbeam-rs/crossbeam/pull/1187)
and has been published in 0.5.15&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rustsec-2025-0024</guid>
    </item>
  </channel>
</rss>
