-
Notifications
You must be signed in to change notification settings - Fork 353
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Import CVE-2023-41051 as RustSec advisory #1766
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks very clear and informative. Thanks for the report!
I've left a suggestion to also add the GHSA alias. If you have no objections, let's commit that and I'll merge.
informational = "unsound" | ||
categories = ["memory-exposure"] | ||
cvss = "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L" | ||
aliases = ["CVE-2023-41051"] |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
aliases = ["CVE-2023-41051"] | |
aliases = ["CVE-2023-41051", "GHSA-49hh-fprx-m68g"] |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Sure, done!
functions = { | ||
"vm_memory::volatile_memory::VolatileMemory::get_atomic_ref" = ["< 0.12.2"], | ||
"vm_memory::volatile_memory::VolatileMemory::aligned_as_ref" = ["< 0.12.2"], | ||
"vm_memory::volatile_memory::VolatileMemory::aligned_as_mut" = ["< 0.12.2"], | ||
"vm_memory::volatile_memory::VolatileMemory::get_ref" = ["< 0.12.2"], | ||
"vm_memory::volatile_memory::VolatileMemory::get_array_ref" = ["< 0.12.2"], | ||
} | ||
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
TOML does not support this syntax, which causes CI to fail. I believe instead of functions = {
you need to write [functions]
and have the rest freestanding: https://toml.io/en/v1.0.0#table
This is a rather surprising corner case of the TOML spec that many people complain about: toml-lang/toml#516
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Alright, let me try, this might take a few attempts, haha
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
whoop, got it!
538c50d
to
84d2dd6
Compare
Signed-off-by: Patrick Roy <[email protected]>
84d2dd6
to
82750a3
Compare
Thanks! |
Hello,
please consider adding this advisory about the
vm_memory
crate to the Rust advisory database.Thank you,
Patrick Roy