Executive brief
unbounded-spsc is a software library used by developers to manage data communication between different parts of a program. A technical error in how the library handles memory during high-speed data transfers can cause a program to crash or behave unpredictably. This could potentially allow an attacker to access sensitive information in the computer's memory or cause a service outage.
Technical details
A vulnerability exists in the `Sender::send` function within `src/lib.rs` due to an incorrect use of `std::mem::transmute`. The code transmutes a raw pointer (`*mut Producer<T>`) into a `Consumer<T>` value, resulting in a 'fake' object that points to the wrong memory location (the `Sender` struct itself instead of the intended buffer). This is triggerable via a Time-of-Check Time-of-Use (TOCTOU) race condition between a sender and a receiver. An attacker can achieve out-of-bounds (OOB) reads and an OOB write/double-free when the fake object is dropped, as the library attempts to decrement a reference count at an invalid address. No patches are currently available.
Affected products
- spearman unbounded-spsc <= 0.2.0
Timeline
- 2026-05-18: advisory: GitHub Security Advisory published
- 2026-06-12: disclosed: CVE published to NVD