CRITICAL
An issue was discovered in the actix-web crate before 0.7.15 for Rust
Published Dec 26, 2021
9.8
CRITICALCVSS 3.1
EPSS 1.32%
Description
An issue was discovered in the actix-web crate before 0.7.15 for Rust. It can add the Send marker trait to an object that cannot be sent between threads safely, leading to memory corruption.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-0512 Advisory
- https://github.com/actix/actix-web/issues/289
- https://github.com/advisories/GHSA-7x36-h62w-vw65 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-25026
- https://raw.githubusercontent.com/rustsec/advisory-db/main/crates/actix-web/RUSTSEC-2018-0019.md x_refsource_MISCThird Party Advisory
- https://rustsec.org/advisories/RUSTSEC-2018-0019.html x_refsource_MISCIssue TrackingThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-0512 | Advisory | |
| https://github.com/actix/actix-web/issues/289 | ||
| https://github.com/advisories/GHSA-7x36-h62w-vw65 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-25026 | ||
| https://raw.githubusercontent.com/rustsec/advisory-db/main/crates/actix-web/RUSTSEC-2018-0019.md | x_refsource_MISCThird Party Advisory | |
| https://rustsec.org/advisories/RUSTSEC-2018-0019.html | x_refsource_MISCIssue TrackingThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 26, 2021
Updated Aug 5, 2024
Reserved Dec 26, 2021
Link CVE-2018-25026
CISA Vulnrichment
No data
Red Hat
No data
GitHub
Link GHSA-7X36-H62W-VW65