A vulnerability was found in tokio-rs bytes up to 1.11.0. It has been classified as problematic. This issue affects the function spare_capacity_mut. The manipulation leads to integer overflow to buffer overflow.

This vulnerability is uniquely identified as CVE-2026-25541. Local access is required to approach this attack. No exploit exists.

Upgrading the affected component is recommended.