CVE Vulnerabilities

CVE-2020-35904

Published: Dec 31, 2020 | Modified: Jan 06, 2021
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

An issue was discovered in the crossbeam-channel crate before 0.4.4 for Rust. It has incorrect expectations about the relationship between the memory allocation and how many iterator elements there are.

Affected Software

Name Vendor Start Version End Version
Crossbeam-channel Crossbeam-channel_project * 0.4.4 (excluding)
Rust-crossbeam-channel Ubuntu groovy *
Rust-crossbeam-channel Ubuntu trusty *
Rust-crossbeam-channel Ubuntu upstream *

References