{"id":"CVE-2022-23639","aliases":["RUSTSEC-2022-0041","GHSA-qc84-gqf4-9926"],"title":"Unsoundness of AtomicCell<*64> arithmetics on 32-bit targets that support Atomic*64","summary":"Unsoundness of AtomicCell<*64> arithmetics on 32-bit targets that support Atomic*64","severity":"none","vendor":"crossbeam-utils","product":"crossbeam-utils","ecosystem":"rust","affected":["crossbeam-utils >= 0.0.0-0, < 0.8.7"],"patched":["crossbeam-utils 0.8.7"],"published":"2022-02-05","updated":"2026-07-17","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/RUSTSEC-2022-0041","references":[{"url":"https://crates.io/crates/crossbeam-utils"},{"url":"https://rustsec.org/advisories/RUSTSEC-2022-0041.html"},{"url":"https://github.com/crossbeam-rs/crossbeam/pull/781"}],"tags":["osv","rust"],"epss":0.01239,"epssPercentile":0.67322,"ingestedAt":"2026-07-17T19:00:51.820Z","slug":"CVE-2022-23639","body":"## Overview\n\n## Impact\n\nAffected versions of this crate incorrectly assumed that the alignment of {i,u}64 was always the same as Atomic{I,U}64.\n\nHowever, the alignment of {i,u}64 on a 32-bit target can be smaller than Atomic{I,U}64.\n\nThis can cause the following problems:\n\n- Unaligned memory accesses\n- Data race\n\nCrates using fetch_* methods with AtomicCell<{i,u}64> are affected by this issue.\n\n32-bit targets without Atomic{I,U}64 and 64-bit targets are not affected by this issue.\n\n32-bit targets with Atomic{I,U}64 and {i,u}64 have the same alignment are also not affected by this issue.\n\nThe following is a complete list of the builtin targets that may be affected. (last update: nightly-2022-02-11)\n\n- armv7-apple-ios (tier 3)\n- armv7s-apple-ios (tier 3)\n- i386-apple-ios (tier 3)\n- i586-unknown-linux-gnu\n- i586-unknown-linux-musl\n- i686-apple-darwin (tier 3)\n- i686-linux-android\n- i686-unknown-freebsd\n- i686-unknown-haiku (tier 3)\n- i686-unknown-linux-gnu\n- i686-unknown-linux-musl\n- i686-unknown-netbsd (tier 3)\n- i686-unknown-openbsd (tier 3)\n- i686-wrs-vxworks (tier 3)\n\n([script to get list](https://gist.github.com/taiki-e/3c7891e8c5f5e0cbcb44d7396aabfe10))\n\n## Patches\n\nThis has been fixed in crossbeam-utils 0.8.7.\n\nAffected 0.8.x releases have been yanked.\n\nThanks to [@taiki-e](https://github.com/taiki-e).\n\n## Affected packages\n\n- `crossbeam-utils >= 0.0.0-0, < 0.8.7`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `crossbeam-utils 0.8.7`","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}