{"id":"GHSA-rwf4-gx62-rqfw","aliases":["RUSTSEC-2022-0029"],"url":"https://o3.security/vulnerability/GHSA-rwf4-gx62-rqfw","summary":"`MsQueue` `push`/`pop` use the wrong orderings","details":"Affected versions of this crate use orderings which are too weak to support this data structure.\nIt is likely this has caused memory corruption in the wild: <https://github.com/crossbeam-rs/crossbeam/issues/97#issuecomment-412785919>.\n","published":"2022-06-08T22:28:27Z","modified":"2023-11-08T04:22:56.497356Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"crossbeam","fixedVersion":"0.3.0"}],"fix":{"url":"https://github.com/crossbeam-rs/crossbeam/pull/98","label":"crossbeam-rs/crossbeam#98"},"references":[{"type":"WEB","url":"https://github.com/crossbeam-rs/crossbeam/issues/97#issuecomment-412785919"},{"type":"WEB","url":"https://github.com/crossbeam-rs/crossbeam/pull/98"},{"type":"PACKAGE","url":"https://github.com/crossbeam-rs/crossbeam"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2022-0029.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T04:22:56.497356Z"}}