{"id":"CVE-2020-15254","aliases":["CVE-2020-35904","GHSA-m8h8-v6jh-c762","GHSA-v5m7-53cv-f3hx","RUSTSEC-2020-0052"],"url":"https://o3.security/vulnerability/CVE-2020-15254","summary":"Incorrect buffer size in crossbeam-channel","details":"Crossbeam is a set of tools for concurrent programming. In crossbeam-channel before version 0.4.4, the bounded channel incorrectly assumes that `Vec::from_iter` has allocated capacity that same as the number of iterator elements. `Vec::from_iter` does not actually guarantee that and may allocate extra memory. The destructor of the `bounded` channel reconstructs `Vec` from the raw pointer based on the incorrect assumes described above. This is unsound and causing deallocation with the incorrect capacity when `Vec::from_iter` has allocated different sizes with the number of iterator elements. This has been fixed in crossbeam-channel 0.4.4.","published":"2020-10-16T17:15:12.057Z","modified":"2026-07-09T11:34:07.393424Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"crates.io","name":"crossbeam-channel","fixedVersion":"0.4.4"}],"fix":{"url":"https://github.com/RustSec/advisory-db/pull/425","label":"RustSec/advisory-db#425"},"references":[{"type":"ADVISORY","url":"https://github.com/crossbeam-rs/crossbeam/security/advisories/GHSA-v5m7-53cv-f3hx"},{"type":"FIX","url":"https://github.com/RustSec/advisory-db/pull/425"},{"type":"FIX","url":"https://github.com/crossbeam-rs/crossbeam/pull/533"},{"type":"EVIDENCE","url":"https://github.com/crossbeam-rs/crossbeam/issues/539"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T11:34:07.393424Z"}}