From 90c47c219637d9bc0dac0afb2ff1e28d769c7cae Mon Sep 17 00:00:00 2001 From: Markus Pettersson Date: Thu, 27 Nov 2025 22:53:33 +0100 Subject: [PATCH] Update RUSTSEC-2025-0126 (#2488) Add patched version number to RUSTSEC-2025-0126. --- crates/nftnl/RUSTSEC-2025-0126.md | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/crates/nftnl/RUSTSEC-2025-0126.md b/crates/nftnl/RUSTSEC-2025-0126.md index 5abf9069..e640cdbd 100644 --- a/crates/nftnl/RUSTSEC-2025-0126.md +++ b/crates/nftnl/RUSTSEC-2025-0126.md @@ -8,7 +8,7 @@ categories = ["memory-corruption"] aliases = ["GHSA-2fjw-whxm-9v4q"] [versions] -patched = [">= 0.8.0"] +patched = [">= 0.9.0"] ``` # Heap-buffer-overflow in nftnl::Batch::with_page_size (nftnl-rs) @@ -21,3 +21,7 @@ batch_page_size .checked_add(crate::nft_nlmsg_maxsize()) .expect("batch_page_size is too large and would overflow"); ``` + +## Mitigation + +Upgrade to version `0.9.0` or later, which aborts instead.