
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-36472 is a vulnerability discovered in the max7301 Rust crate, disclosed on December 18, 2020. The vulnerability affects versions prior to 0.2.0 of the max7301 package, which is used for hardware expansion functionality. The issue involves thread safety violations in the ImmediateIO and TransactionalIO types (RustSec Advisory).
The vulnerability stems from incorrect implementation of the Sync trait for ImmediateIO and TransactionalIO types. These types implement Sync for all contained Expander types regardless of whether the Expander itself is thread-safe. Since the IO types allow retrieving the Expander, this can result in non-thread safe types being sent across threads as part of the Expander, potentially leading to data races (RustSec Advisory).
The vulnerability can lead to data races in concurrent environments, potentially causing memory corruption and application instability. The CVSS score is 5.9 (Medium), with high attack complexity and potential high impact on availability, though no impact on confidentiality or integrity (RustSec Advisory).
The vulnerability has been patched in version 0.2.0 of the max7301 crate. Users are advised to upgrade to version 0.2.0 or later to address this security issue (RustSec Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."