CVE-2020-35905: Race Condition
Published Dec 31, 2020
·Updated
An issue was discovered in the futures-util crate before 0.3.7 for Rust. MutexGuard::map can cause a data race for certain closure situations (in safe code).
Affected Software
1 affected component
rust-lang Future-utils Rust<0.3.7
Remediation
Patch Available
Event History
Dec 31, 2020
CVE Published
via MITRE·08:21 AM
Data Sourced
via MITRE·08:21 AM
Description
Frequently Asked Questions
1
What is CVE-2020-35905?
CVE-2020-35905 is an issue discovered in the futures-util crate before 0.3.7 for Rust, where MutexGuard::map can cause a data race for certain closure situations.
2
What software is affected by CVE-2020-35905?
The software affected by CVE-2020-35905 is Rust-lang Future-utils versions up to and exclusive of 0.3.7.
3
What is the severity of CVE-2020-35905?
CVE-2020-35905 has a severity rating of medium with a value of 4.7.
4
How can I fix CVE-2020-35905?
To fix CVE-2020-35905, upgrade the futures-util crate to version 0.3.7 or later.
5
Where can I find more information about CVE-2020-35905?
More information about CVE-2020-35905 can be found at https://rustsec.org/advisories/RUSTSEC-2020-0059.html.