From 9b3641d0aafcae14446bba35a41fef4f607d9c51 Mon Sep 17 00:00:00 2001 From: Georgios Androutsopoulos Date: Thu, 14 Aug 2025 15:49:42 -0400 Subject: [PATCH] HBOF due to user-defined implementations of scratchpad::Tracking (fix note) --- crates/scratchpad/RUSTSEC-0000-0000.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/crates/scratchpad/RUSTSEC-0000-0000.md b/crates/scratchpad/RUSTSEC-0000-0000.md index 63beff89..4db4b760 100644 --- a/crates/scratchpad/RUSTSEC-0000-0000.md +++ b/crates/scratchpad/RUSTSEC-0000-0000.md @@ -22,4 +22,4 @@ The `get` and `set` methods of the public trait `scratchpad::Tracking` interact This becomes problematic because even safe implementations of `get` and `set`-written without using any unsafe code-can still result in ill-formed raw pointers. These pointers may later be dereferenced within safe APIs of the crate (e.g., `marker::MarkerBack::allocate_slice_copy`), potentially leading to arbitrary memory access or heap buffer overflows. -According to the [penultimate commit](https://github.com/okready/scratchpad/commit/957dee1a3902f48600b06910e8e0b1d5ee7dab83), the crate is in maintenance mode awaiting a cleanup that will reduce the area of unsafe code. +According to the [penultimate commit](https://github.com/okready/scratchpad/commit/957dee1a3902f48600b06910e8e0b1d5ee7dab83), the crate is in maintenance mode awaiting a cleanup that will reduce the area of unsafe code. Note that the last commits to the repository are from 4 years ago. \ No newline at end of file