CVE-2026-54906

EUVD-2026-38811
concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReadWriteLock#release_write_lock does not verify that the calling thread acquired the write lock. Any thread with access to the lock object can release an active write lock held by another thread. A second writer can then enter its critical section while the first writer is still running. Concurrent::ReadWriteLock#release_read_lock also decrements the shared counter even when no read lock is held. Calling it on a fresh lock changes the counter from 0 to -1, after which normal read acquisition raises Concurrent::ResourceLimitError. This is a synchronization correctness issue in the public Concurrent::ReadWriteLock API. This vulnerability is fixed in 1.3.7.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 5.66%
Affected Products (NVD)
VendorProductVersion
rubyconcurrencyconcurrent_ruby
𝑥
< 1.3.7
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ruby-concurrent
bookworm
postponed
bullseye
postponed
forky
1.3.8-1
fixed
sid
1.3.8-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ruby-concurrent
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
Azure Linux logo
Azure Linux Releases
Azure Package
Release
rubygem-concurrent-ruby
Azure Linux 3.0
0:1.3.7-1.azl3
fixed