<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 23:37:58 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-4574 — Crossbeam-channel: crossbeam-channel vulnerable to double free on drop</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-4574</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crossbeam-channel, Red Hat Directory Server 11, Red Hat Directory Server 12, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat Satellite 6 and 2 more&lt;/p&gt;
&lt;p&gt;In crossbeam-channel rust crate, the internal `Channel` type&amp;#39;s `Drop` method has a race condition which could, in some circumstances, lead to a double-free that could result in memory corruption.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crossbeam-channel, Red Hat Directory Server 11, Red Hat Directory Server 12, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat Satellite 6 and 2 more&lt;/p&gt;
&lt;p&gt;In crossbeam-channel rust crate, the internal `Channel` type&amp;#39;s `Drop` method has a race condition which could, in some circumstances, lead to a double-free that could result in memory corruption.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-4574</guid>
    </item>
    <item>
      <title>GHSA-pg9f-39pc-qf8g — crossbeam-channel Vulnerable to Double Free on Drop</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pg9f-39pc-qf8g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: crossbeam-channel&lt;/p&gt;
&lt;p&gt;The internal `Channel` type&amp;#39;s `Drop` method has a race
which could, in some circumstances, lead to a double-free.
This could result in memory corruption.&lt;/p&gt;
&lt;p&gt;Quoting from the
[upstream description in merge request \#1187](https://github.com/crossbeam-rs/crossbeam/pull/1187#issue-2980761131):&lt;/p&gt;
&lt;p&gt;&amp;gt; The problem lies in the fact that `dicard_all_messages` contained two paths that could lead to `head.block` being read but only one of them would swap the value. This meant that `dicard_all_messages` could end up observing a non-null block pointer (and therefore attempting to free it) without setting `head.block` to null. This would then lead to `Channel::drop` making a second attempt at dropping the same pointer.&lt;/p&gt;
&lt;p&gt;The bug was introduced while fixing a memory leak, in
upstream [MR \#1084](https://github.com/crossbeam-rs/crossbeam/pull/1084),
first published in 0.5.12.&lt;/p&gt;
&lt;p&gt;The fix is in
upstream [MR \#1187](https://github.com/crossbeam-rs/crossbeam/pull/1187)
and has been published in 0.5.15&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: crossbeam-channel&lt;/p&gt;
&lt;p&gt;The internal `Channel` type&amp;#39;s `Drop` method has a race
which could, in some circumstances, lead to a double-free.
This could result in memory corruption.&lt;/p&gt;
&lt;p&gt;Quoting from the
[upstream description in merge request \#1187](https://github.com/crossbeam-rs/crossbeam/pull/1187#issue-2980761131):&lt;/p&gt;
&lt;p&gt;&amp;gt; The problem lies in the fact that `dicard_all_messages` contained two paths that could lead to `head.block` being read but only one of them would swap the value. This meant that `dicard_all_messages` could end up observing a non-null block pointer (and therefore attempting to free it) without setting `head.block` to null. This would then lead to `Channel::drop` making a second attempt at dropping the same pointer.&lt;/p&gt;
&lt;p&gt;The bug was introduced while fixing a memory leak, in
upstream [MR \#1084](https://github.com/crossbeam-rs/crossbeam/pull/1084),
first published in 0.5.12.&lt;/p&gt;
&lt;p&gt;The fix is in
upstream [MR \#1187](https://github.com/crossbeam-rs/crossbeam/pull/1187)
and has been published in 0.5.15&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pg9f-39pc-qf8g</guid>
    </item>
  </channel>
</rss>
