CVE-2026-54905CWE-128

concurrent-ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity

Low · published June 24, 2026

CVSS v4.0
2.0
EPSS
0%
Percentile
4.7
In the wild
Unconfirmed
What it is

concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReentrantReadWriteLock can incorrectly grant a write lock after one thread acquires the read lock 32,768 times. The lock stores a thread's local read and write hold counts in one integer. The low 15 bits are used for the read hold count, and bit 15 is used as WRITE_LOCK_HELD. After 32,768 reentrant read acquisitions, the local read count crosses into the write-lock bit. try_write_lock then treats the thread as already holding a write lock and returns true without setting the global RUNNING_WRITER bit. This breaks the core mutual-exclusion guarantee: the caller is told it has a write lock, but other threads can still hold or acquire read locks at the same time. This vulnerability is fixed in 1.3.7.

The record
Technical detail
CVSS v4.0
2.0 · LOW
Vector
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
EPSS
0.00153 · 4.7th percentile
Weakness
CWE-128 · Wrap-around Error
Published
2026-06-24T15:42Z
EPSS history
Timeline
  • 24 JUN 15:42Z
    concurrent-ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity
    cvelistv5