UBUNTU-CVE-2018-25026

Source
https://ubuntu.com/security/CVE-2018-25026
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-25026.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2018-25026
Upstream
Published
2021-12-27T00:15:00Z
Modified
2026-01-20T17:03:10.644627Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

An issue was discovered in the actix-web crate before 0.7.15 for Rust. It can add the Send marker trait to an object that cannot be sent between threads safely, leading to memory corruption.

References

Affected packages

Ubuntu:20.04:LTS / rust-actix-derive

Package

Name
rust-actix-derive
Purl
pkg:deb/ubuntu/rust-actix-derive@0.5.0-2?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.5.0-1
0.5.0-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "librust-actix-derive-dev",
            "binary_version": "0.5.0-2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-25026.json"

Ubuntu:22.04:LTS / rust-actix-derive

Package

Name
rust-actix-derive
Purl
pkg:deb/ubuntu/rust-actix-derive@0.5.0-2?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.5.0-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "librust-actix-derive-dev",
            "binary_version": "0.5.0-2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-25026.json"

Ubuntu:24.04:LTS / rust-actix-derive

Package

Name
rust-actix-derive
Purl
pkg:deb/ubuntu/rust-actix-derive@0.5.0-2?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.5.0-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "librust-actix-derive-dev",
            "binary_version": "0.5.0-2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-25026.json"

Ubuntu:25.10 / rust-actix-derive

Package

Name
rust-actix-derive
Purl
pkg:deb/ubuntu/rust-actix-derive@0.5.0-2?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.5.0-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "librust-actix-derive-dev",
            "binary_version": "0.5.0-2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-25026.json"