<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 21:12:03 +0000</lastBuildDate>
    <item>
      <title>CVE-2023-22466 — Tokio's reject_remote_clients configuration may get dropped when creating a Windows named pipe</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2023-22466</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; tokio-rs tokio&lt;/p&gt;
&lt;p&gt;Tokio is a runtime for writing applications with Rust. Starting with version 1.7.0 and prior to versions 1.18.4, 1.20.3, and 1.23.1, when configuring a Windows named pipe server, setting `pipe_mode` will reset `reject_remote_clients` to `false`. If the application has previously configured `reject_remote_clients` to `true`, this effectively undoes the configuration. Remote clients may only access the named pipe if the named pipe&amp;#39;s associated path is accessible via a publicly shared folder (SMB). Versions 1.23.1, 1.20.3, and 1.18.4 have been patched. The fix will also be present in all releases starting from version 1.24.0. Named pipes were introduced to Tokio in version 1.7.0, so releases older than 1.7.0 are not affected. As a workaround, ensure that `pipe_mode` is set first after initializing a `ServerOptions`.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; tokio-rs tokio&lt;/p&gt;
&lt;p&gt;Tokio is a runtime for writing applications with Rust. Starting with version 1.7.0 and prior to versions 1.18.4, 1.20.3, and 1.23.1, when configuring a Windows named pipe server, setting `pipe_mode` will reset `reject_remote_clients` to `false`. If the application has previously configured `reject_remote_clients` to `true`, this effectively undoes the configuration. Remote clients may only access the named pipe if the named pipe&amp;#39;s associated path is accessible via a publicly shared folder (SMB). Versions 1.23.1, 1.20.3, and 1.18.4 have been patched. The fix will also be present in all releases starting from version 1.24.0. Named pipes were introduced to Tokio in version 1.7.0, so releases older than 1.7.0 are not affected. As a workaround, ensure that `pipe_mode` is set first after initializing a `ServerOptions`.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2023-22466</guid>
    </item>
    <item>
      <title>GHSA-7rrj-xr53-82p7 — Tokio reject_remote_clients configuration may get dropped when creating a Windows named pipe</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7rrj-xr53-82p7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: tokio&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;When configuring a Windows named pipe server, setting `pipe_mode` will reset `reject_remote_clients` to `false`. If the application has previously configured `reject_remote_clients` to `true`, this effectively undoes the configuration. This also applies if `reject_remote_clients` is not explicitly set as this is the default configuration and is cleared by calling `pipe_mode`.&lt;/p&gt;
&lt;p&gt;Remote clients may only access the named pipe if the named pipe&amp;#39;s associated path is accessible via a publically shared folder (SMB).&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;The following versions have been patched:
* 1.23.1
* 1.20.3
* 1.18.4&lt;/p&gt;
&lt;p&gt;The fix will also be present in all releases starting from version 1.24.0.&lt;/p&gt;
&lt;p&gt;Named pipes were introduced to Tokio in version 1.7.0, so releases older than 1.7.0 are not affected.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Ensure that `pipe_mode` is set **first** after initializing a `ServerOptions`. For example:&lt;/p&gt;
&lt;p&gt;```rust
let mut opts = ServerOptions::new();
opts.pipe_mode(PipeMode::Message);
opts.reject_remote_clients(true);
```&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;https://learn.microsoft.com/en-us/windows/win32/api/winbase/nf-winbase-createnamedpipea#pipe_reject_remote_clients&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: tokio&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;When configuring a Windows named pipe server, setting `pipe_mode` will reset `reject_remote_clients` to `false`. If the application has previously configured `reject_remote_clients` to `true`, this effectively undoes the configuration. This also applies if `reject_remote_clients` is not explicitly set as this is the default configuration and is cleared by calling `pipe_mode`.&lt;/p&gt;
&lt;p&gt;Remote clients may only access the named pipe if the named pipe&amp;#39;s associated path is accessible via a publically shared folder (SMB).&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;The following versions have been patched:
* 1.23.1
* 1.20.3
* 1.18.4&lt;/p&gt;
&lt;p&gt;The fix will also be present in all releases starting from version 1.24.0.&lt;/p&gt;
&lt;p&gt;Named pipes were introduced to Tokio in version 1.7.0, so releases older than 1.7.0 are not affected.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Ensure that `pipe_mode` is set **first** after initializing a `ServerOptions`. For example:&lt;/p&gt;
&lt;p&gt;```rust
let mut opts = ServerOptions::new();
opts.pipe_mode(PipeMode::Message);
opts.reject_remote_clients(true);
```&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;https://learn.microsoft.com/en-us/windows/win32/api/winbase/nf-winbase-createnamedpipea#pipe_reject_remote_clients&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7rrj-xr53-82p7</guid>
    </item>
  </channel>
</rss>
