{"api_version":"1","generated_at":"2026-07-23T10:06:09+00:00","cve":"CVE-2019-16137","urls":{"html":"https://cve.report/CVE-2019-16137","api":"https://cve.report/api/cve/CVE-2019-16137.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-16137","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-16137"},"summary":{"title":"CVE-2019-16137","description":"An issue was discovered in the spin crate before 0.5.2 for Rust, when RwLock is used. Because memory ordering is mishandled, two writers can acquire the lock at the same time, violating mutual exclusion.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-09-09 12:15:00","updated_at":"2020-08-24 17:37:00"},"problem_types":["CWE-662"],"metrics":[],"references":[{"url":"https://rustsec.org/advisories/RUSTSEC-2019-0013.html","name":"https://rustsec.org/advisories/RUSTSEC-2019-0013.html","refsource":"MISC","tags":["Third Party Advisory"],"title":"About RustSec › RustSec Advisory Database","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-16137","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-16137","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"16137","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"spin-rs_project","cpe5":"spin-rs","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"16137","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"spin-rs_project","cpe5":"spin-rs","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2019-16137","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in the spin crate before 0.5.2 for Rust, when RwLock is used. Because memory ordering is mishandled, two writers can acquire the lock at the same time, violating mutual exclusion."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://rustsec.org/advisories/RUSTSEC-2019-0013.html","refsource":"MISC","name":"https://rustsec.org/advisories/RUSTSEC-2019-0013.html"}]}},"nvd":{"publishedDate":"2019-09-09 12:15:00","lastModifiedDate":"2020-08-24 17:37:00","problem_types":["CWE-662"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:C","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE","baseScore":7.8},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:spin-rs_project:spin-rs:*:*:*:*:*:*:*:*","versionEndExcluding":"0.5.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"16137","Ordinal":"155707","Title":"CVE-2019-16137","CVE":"CVE-2019-16137","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"16137","Ordinal":"1","NoteData":"An issue was discovered in the spin crate before 0.5.2 for Rust, when RwLock is used. Because memory ordering is mishandled, two writers can acquire the lock at the same time, violating mutual exclusion.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"16137","Ordinal":"2","NoteData":"2019-09-09","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"16137","Ordinal":"3","NoteData":"2019-09-09","Type":"Other","Title":"Modified"}]}}}