Description
unbounded_spsc is an "unbounded" extension of bounded_spsc_queue. In versions 0.2.0 and prior, sender::send pointer-as-value transmute causes OOB read and fake-Arc drop under TX/RX race. At time of publication, there are no publicly available patches.
Published: 2026-06-12
Score: 5.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-6m57-8r3p-pqx6 unbounded-spsc: Sender::send pointer-as-value transmute causes OOB read and fake-Arc drop under TX/RX race
History

Tue, 16 Jun 2026 00:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:spearman:unbounded-spsc:*:*:*:*:*:*:*:*

Fri, 12 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Spearman
Spearman unbounded-spsc
Vendors & Products Spearman
Spearman unbounded-spsc

Fri, 12 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 12 Jun 2026 15:45:00 +0000

Type Values Removed Values Added
Description unbounded_spsc is an "unbounded" extension of bounded_spsc_queue. In versions 0.2.0 and prior, sender::send pointer-as-value transmute causes OOB read and fake-Arc drop under TX/RX race. At time of publication, there are no publicly available patches.
Title unbounded-spsc: Sender::send pointer-as-value transmute causes OOB read and fake-Arc drop under TX/RX race
Weaknesses CWE-125
CWE-415
CWE-704
CWE-787
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H'}


Subscriptions

Spearman Unbounded-spsc
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-06-12T15:54:30.265Z

Reserved: 2026-05-15T21:46:51.548Z

Link: CVE-2026-46690

cve-icon Vulnrichment

Updated: 2026-06-12T15:53:25.480Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-12T16:16:29.197

Modified: 2026-06-16T00:07:05.163

Link: CVE-2026-46690

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-12T20:20:02Z