A vulnerability was found in ruby-concurrency concurrent-ruby up to 1.3.6. It has been rated as problematic. This issue affects the function Concurrent::ReadWriteLock#release_write_lock. The manipulation leads to missing lock check.

This vulnerability is traded as CVE-2026-54906. An attack has to be approached locally. There is no exploit available.

Upgrading the affected component is advised.