CVE-2021-45710 — tokio
HIGHCVE-2021-45710 is a high-severity (CVSS 8.1) CWE-362 vulnerability in tokio. A fix is available for tokio — see the affected versions and patch details below.
Race Condition in tokio
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
How urgent is this, really
CVE-2021-45710 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.
Where this sits among everything scored
Of 385,386 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.
Real-World Exposure
tokio🦀tokioReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects crates.io packages — download data is not available via public APIs for these ecosystems.
Description
If a tokio::sync::oneshot channel is closed (via the oneshot::Receiver::close method), a data race may occur if the oneshot::Sender::send method is called while the corresponding oneshot::Receiver is awaited or calling try_recv.
When these methods are called concurrently on a closed channel, the two halves of the channel can concurrently access a shared memory location, resulting in a data race. This has been observed to cause memory corruption.
Note that the race only occurs when both halves of the channel are used after the Receiver half has called close. Code where close is not used, or where the Receiver is not awaited and try_recv is not called after calling close, is not affected.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 🦀crates.io | tokio | ≥ 0.1.14&&< 1.8.4 | 1.8.4cargo update -p tokio --precise 1.8.4 |
| 🦀crates.io | tokio | ≥ 1.9.0&&< 1.13.1 | 1.13.1cargo update -p tokio --precise 1.13.1 |
Affected Products
tokiotokioDetection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for tokio, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update tokio to 1.8.4 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2021-45710 is resolved across your whole dependency graph.
Workarounds
Constrain what reaches the vulnerable code: limit the size and shape of untrusted input, isolate the affected component in a sandboxed or least-privileged process, and enable the platform's memory-safety mitigations (ASLR, stack protector, hardened allocator) so an out-of-bounds access is more likely to fail closed than to be exploitable.
Frequently Asked Questions
Is CVE-2021-45710 in your dependencies?
Find it across crates.io, including transitive dependencies.