CVE-2023-6180
Rust vulnerability analysis and mitigation

Overview

The tokio-boring library version 4.0.0 is affected by a memory leak vulnerability (CVE-2023-6180) that was discovered and disclosed in December 2023. The vulnerability affects the set_ex_data function in the library, which fails to properly deallocate memory after completing TLS connections (Vendor Advisory).

Technical details

The vulnerability stems from a memory management issue where the set_ex_data function does not properly deallocate memory used by pre-existing data after completing TLS connections. The vulnerability has been assigned a CVSS v3.1 base score of 5.3 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L. The issue is classified under multiple CWE categories including CWE-401 (Missing Release of Memory after Effective Lifetime), CWE-404 (Improper Resource Shutdown or Release), and CWE-400 (Uncontrolled Resource Consumption) (NVD).

Impact

The vulnerability can lead to excessive resource consumption and potential Denial of Service (DoS) through resource exhaustion. Each new TLS connection causes the program to consume more resources as memory is not properly deallocated, leading to a progressive increase in memory usage over time (Vendor Advisory).

Mitigation and workarounds

The vulnerability has been fixed in version 4.1.0 of tokio-boring. Users are advised to upgrade to this patched version to address the memory leak issue (Vendor Advisory).

Additional resources


SourceThis report was generated using AI

Related Rust vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-22698HIGH8.7
  • RustRust
  • sm2
NoNoJan 10, 2026
CVE-2026-22700HIGH7.5
  • RustRust
  • sm2
NoNoJan 10, 2026
CVE-2026-22699HIGH7.5
  • RustRust
  • sm2
NoNoJan 10, 2026
CVE-2026-22705MEDIUM6.4
  • RustRust
  • ml-dsa
NoYesJan 10, 2026
CVE-2025-15504MEDIUM4.8
  • PythonPython
  • lief
NoYesJan 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management