GHSA-mqwx-r894-9hfp

Suggest an improvement
Source
https://github.com/advisories/GHSA-mqwx-r894-9hfp
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/05/GHSA-mqwx-r894-9hfp/GHSA-mqwx-r894-9hfp.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-mqwx-r894-9hfp
Aliases
  • CVE-2025-48752
Published
2025-05-24T03:30:19Z
Modified
2025-05-27T18:29:34.239861Z
Severity
  • 2.9 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
Process Sync has a Potential Unsound Issue in SharedMutex
Details

In the process-sync crate 0.2.2 for Rust, the drop function lacks a check for whether the pthread_mutex is unlocked.

Database specific
{
    "nvd_published_at": "2025-05-24T03:15:23Z",
    "cwe_ids": [
        "CWE-416"
    ],
    "severity": "LOW",
    "github_reviewed": true,
    "github_reviewed_at": "2025-05-27T18:04:16Z"
}
References

Affected packages

crates.io / process-sync

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
0.2.2