Descriptioncrossbeam-deque is a package of work-stealing deques for building task schedulers when programming in Rust. In versions prior to 0.7.4 and 0.8.0, the result of the race condition is that one or more tasks in the worker queue can be popped twice instead of other tasks that are forgotten and never popped. If tasks are allocated on the heap, this can cause double free and a memory leak. If not, this still can cause a logical bug. Crates using `Stealer::steal`, `Stealer::steal_batch`, or `Stealer::steal_batch_and_pop` are affected by this issue. This has been fixed in crossbeam-deque 0.8.1 and 0.7.4.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub advisories/code/issues, web search, more)
Debian Bugs993146

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
firefox (PTS)sid111.0.1-1fixed
firefox-esr (PTS)buster91.12.0esr-1~deb10u1fixed
buster (security)102.9.0esr-1~deb10u1fixed
bullseye (security)102.9.0esr-1~deb11u1fixed
bookworm, sid102.9.0esr-2fixed
rust-crossbeam-deque (PTS)buster0.6.3-1vulnerable
bookworm, sid0.8.1-1fixed
thunderbird (PTS)buster1:91.12.0-1~deb10u1fixed
buster (security)1:102.9.0-1~deb10u1fixed
bullseye (security)1:102.9.0-1~deb11u1fixed
bookworm, sid1:102.9.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
firefox-esrsource(unstable)(not affected)
thunderbirdsource(unstable)(not affected)


- firefox-esr <not-affected> (Only affect Firefox 91 not in any supported suite in vulnerable version)
- thunderbird <not-affected> (Only affects Thunderbird 91 not in any supported suite in vulnerable version)
[bullseye] - rust-crossbeam-deque <no-dsa> (Minor issue)
[buster] - rust-crossbeam-deque <no-dsa> (Minor issue)

