PatchSiren

spearman CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM spearman CVE published 2026-06-12

CVE-2026-46690

CVE-2026-46690 is a vulnerability in the unbounded_spsc extension of bounded_spsc_queue, affecting versions 0.2.0 and prior. The issue arises from the sender::send pointer-as-value transmute, which causes an out-of-bounds (OOB) read and fake-Arc drop under a TX/RX race condition. At the time of publication, there are no publicly available patches for this vulnerability.