Double free in crossbeam-channel - CVE-2025-4574
Published: September 3, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the the internal `Channel` type's `Drop` method. A remote attacker can pass specially crafted data to the application, trigger a double free error and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Maximo Application Suite - Edge Data Collector
Fedora
openSUSE Leap
keylime-agent-rust
awatcher
rust-sevctl
tuigreet
rust-hashlink
rust-kbs-types
ruff
rust-rusqlite
python-watchfiles
gotify-desktop
python311-maturin
maturin
libkrun
rust-git-interactive-rebase-tool
mirrorlist-server
rust-sev
atuin
How to mitigate CVE-2025-4574
Maximo Application Suite - Edge Data Collector - addressed in versions 8.11.21, 9.0.13, 9.1.3
keylime-agent-rust - update to 0.2.7-5.fc41
awatcher - addressed in versions 0.3.1-2.fc41, 0.3.1-2.fc42, 0.3.1-2.fc43
rust-sevctl - addressed in versions 0.6.2-3.fc41, 0.6.2-3.fc42, 0.6.2-3.fc43
tuigreet - addressed in versions 0.9.1-4.fc41, 0.9.1-4.fc42, 0.9.1-4.fc43
rust-hashlink - addressed in versions 0.10.0-1.el10_1, 0.10.0-1.fc41, 0.10.0-1.fc42
rust-kbs-types - addressed in versions 0.11.0-1.fc41, 0.11.0-1.fc42, 0.11.0-1.fc43
ruff - addressed in versions 0.11.5-2.el10_1, 0.11.5-2.fc41, 0.11.5-2.fc42
rust-rusqlite - addressed in versions 0.31.0-6.el10_1, 0.31.0-6.fc41, 0.31.0-6.fc42
python-watchfiles - addressed in versions 1.0.3-4.fc41, 1.0.4-5.el10_0, 1.0.4-5.el10_1, 1.0.4-5.fc42, 1.0.5-3.fc43
gotify-desktop - addressed in versions 1.3.7-5.fc41, 1.3.7-5.fc42, 1.3.7-5.fc43
python311-maturin - update to 1.4.0-150600.3.6.1
maturin - addressed in versions 1.8.6-1.fc41, 1.8.6-1.fc42
libkrun - addressed in versions 1.13.0-1.fc41, 1.13.0-1.fc42, 1.13.0-1.fc43
rust-git-interactive-rebase-tool - addressed in versions 2.4.1-9.fc41, 2.4.1-9.fc42, 2.4.1-9.fc43
mirrorlist-server - addressed in versions 3.0.7-7.fc41, 3.0.7-7.fc42, 3.0.7-7.fc43
rust-sev - addressed in versions 6.1.0-2.fc41, 6.1.0-2.fc42, 6.1.0-2.fc43
atuin - addressed in versions 18.3.0-4.el9, 18.3.0-4.fc41, 18.3.0-4.fc42, 18.3.0-4.fc43
External References
Related Security Bulletins
- Remote code execution in crossbeam-channel rust crate
- Fedora 43 update for python-watchfiles
- Fedora 42 update for python-watchfiles
- Fedora 41 update for python-watchfiles
- Fedora EPEL 10.1 update for python-watchfiles
- Fedora EPEL 10.0 update for python-watchfiles
- Fedora 41 update for ruff, rust-hashlink, rust-rusqlite
- Fedora EPEL 10.1 update for ruff, rust-hashlink, rust-rusqlite
- Fedora 42 update for maturin
- Fedora 41 update for maturin
- Fedora 42 update for ruff, rust-hashlink, rust-rusqlite
- Fedora 43 update for libkrun, rust-kbs-types, rust-sev, rust-sevctl
- Fedora 42 update for libkrun, rust-kbs-types, rust-sev, rust-sevctl
- Fedora 41 update for libkrun, rust-kbs-types, rust-sev, rust-sevctl
- Fedora 41 update for tuigreet
- Fedora 42 update for tuigreet
- Fedora 43 update for tuigreet
- SUSE update for python-maturin
- IBM Edge Data Collector update for crossbeam-channel rust crate
- Fedora 43 update for rust-git-interactive-rebase-tool
- Fedora 41 update for rust-git-interactive-rebase-tool
- Fedora 42 update for rust-git-interactive-rebase-tool
- Fedora 43 update for atuin, awatcher, gotify-desktop, mirrorlist-server
- Fedora 42 update for atuin, awatcher, gotify-desktop, mirrorlist-server
- Fedora 41 update for atuin, awatcher, gotify-desktop, keylime-agent-rust, mirrorlist-server
- Fedora EPEL 9 update for atuin