Vulnerability DatabaseRUSTSEC-2024-0019

RUSTSEC-2024-0019
Rust vulnerability analysis and mitigation

Overview

RUSTSEC-2024-0019 (CVE-2024-27308) is a security vulnerability affecting the Mio crate for Rust, specifically impacting versions between 0.7.2 and 0.8.10. The vulnerability involves tokens for named pipes being delivered after deregistration on Windows systems, potentially leading to use-after-free issues (GitHub Advisory).

Technical details

The vulnerability occurs when using named pipes on Windows, where Mio may return invalid tokens corresponding to named pipes that have already been deregistered from the Mio registry. This breaks Mio's guarantee that once an IO resource is deregistered, its token should never be returned again. The issue is Windows-specific and only affects named pipe implementations. The vulnerability has been assigned a High severity rating and is particularly serious for applications using Tokio v1.30.0 or later (GitHub Advisory).

Impact

The impact varies depending on how Mio is implemented in applications. In some cases, invalid tokens may only result in warnings or crashes. However, in applications that store pointers in tokens, this vulnerability can lead to use-after-free vulnerabilities. The issue is particularly severe for users of the Tokio framework, where it can consistently result in use-after-free conditions (GitHub Advisory).

Exploitability

The vulnerability is exploitable only on Windows systems and specifically requires the use of named pipes. The issue affects Mio versions between 0.7.2 and 0.8.10, and becomes particularly dangerous when used with Tokio version 1.30.0 or later. Earlier versions of Tokio (prior to v1.30.0) are not vulnerable as they ignore invalid tokens (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in Mio version 0.8.11. For users unable to upgrade immediately, a workaround exists where vulnerable libraries using Mio can detect and ignore invalid tokens. Users are strongly encouraged to upgrade to the patched version to ensure system security (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Rust vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-24890MEDIUM6.8
  • Rust logoRust
  • cargo-c
NoYesSep 09, 2026
CVE-2026-53956MEDIUM5.4
  • Python logoPython
  • py-rattler
NoYesSep 09, 2026
RUSTSEC-2026-0282NONEN/A
  • Rust logoRust
  • aligned_box
NoYesSep 09, 2026
RUSTSEC-2026-0281NONEN/A
  • Rust logoRust
  • greentic-setup
NoYesSep 07, 2026
RUSTSEC-2026-0280NONEN/A
  • Rust logoRust
  • greentic-setup-dev
NoYesSep 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management