Skip to content

Conversation

@austinhartzheim
Copy link
Contributor

Add advisory for a memory exposure in the Deserialize implementation for nalgebra's VecStorage/MatrixVec structs, as discussed in #880.

git bisect was used to track this vulnerability back to its introduction in 086e6e. git tag --contains 086e6e indicates that the first tag containing this commit is v0.11.0. I have marked earlier versions as unaffected by this advisory.

@Shnatsel
Copy link
Member

Shnatsel commented Jun 6, 2021

Looks good to me. Thanks!

@Shnatsel Shnatsel merged commit 46e657b into rustsec:main Jun 6, 2021
@austinhartzheim austinhartzheim deleted the issue-880 branch June 6, 2021 17:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants