Junglewise Threat Intelligence

CVE-2026-46690: spearman unbounded-spsc memory corruption in Sender::send

CVE-2026-46690 · Severity: medium · CVSS 5.8 · Published 2026-06-12

Vendors: crates.io.

Executive brief

unbounded-spsc is a software library used by developers to manage data communication between different parts of a program. A technical error in how the library handles memory during high-speed data transfers can cause a program to crash or behave unpredictably. This could potentially allow an attacker to access sensitive information in the computer's memory or cause a service outage.

Technical details

A vulnerability exists in the `Sender::send` function within `src/lib.rs` due to an incorrect use of `std::mem::transmute`. The code transmutes a raw pointer (`*mut Producer<T>`) into a `Consumer<T>` value, resulting in a 'fake' object that points to the wrong memory location (the `Sender` struct itself instead of the intended buffer). This is triggerable via a Time-of-Check Time-of-Use (TOCTOU) race condition between a sender and a receiver. An attacker can achieve out-of-bounds (OOB) reads and an OOB write/double-free when the fake object is dropped, as the library attempts to decrement a reference count at an invalid address. No patches are currently available.

Affected products

  • spearman unbounded-spsc <= 0.2.0

Timeline

  • 2026-05-18: advisory: GitHub Security Advisory published
  • 2026-06-12: disclosed: CVE published to NVD

References