Commit Graph

2515 Commits

Author SHA1 Message Date
djc
6366de025d Assigned RUSTSEC-2025-0058 to custom_derive 2025-09-07 10:38:20 +02:00
John Vandenberg
15591dc0c7 Add unmaintained advisory for custom_derive 2025-09-07 08:18:03 +02:00
djc
d6c6489daf Assigned RUSTSEC-2025-0057 to fxhash 2025-09-05 21:09:01 +02:00
Sam
dbaedaed96 Add advisory for unmaintained fxhash crate 2025-09-05 21:02:11 +02:00
djc
01f8f6b36e Assigned RUSTSEC-2025-0056 to adler 2025-09-05 11:05:48 +02:00
John Vandenberg
0feb7c883b Add unmaintained advisory for adler 2025-09-05 10:55:15 +02:00
djc
20a8af2bdc Assigned RUSTSEC-2025-0055 to tracing-subscriber 2025-09-02 13:05:02 +02:00
Eli Wenig
6ba91d3fd4 add CVE-2025-58160 details to tracing-subscriber (#2377) 2025-09-02 13:04:04 +02:00
djc
97dec1d752 Assigned RUSTSEC-2025-0054 to array-queue 2025-09-01 14:55:53 +02:00
George Androutsopoulos
ad75531bdb The API ArrayQueue::push_front is not panic-safe (#2363)
* ArrayQueue::push_front is not panic-safe

* Add patch info

---------

Co-authored-by: Georgios Androutsopoulos <georgeandrout@gamac.local>
2025-09-01 14:54:09 +02:00
djc
ed23fda8bc Assigned RUSTSEC-2025-0053 to arenavec 2025-09-01 09:59:00 +02:00
George Androutsopoulos
835b4f6331 Multiple memory corruption vulnerabilities in arenavec (#2364)
Co-authored-by: Georgios Androutsopoulos <georgeandrout@gamac.local>
2025-09-01 09:58:09 +02:00
John Vandenberg
01ca7adeec Remove unaffected from RUSTSEC-2020-0095.md 2025-08-30 08:09:56 +02:00
github-actions[bot]
53af8988c5 Assigned RUSTSEC-2024-0443 to webp (#2374)
Co-authored-by: Shnatsel <291257+Shnatsel@users.noreply.github.com>
2025-08-29 17:09:41 +01:00
Sergey "Shnatsel" Davidoff
7626fd2d51 Advisory for WebP encoder soundness (#2373)
* Advisory for WebP encoder soundness

* many functions are affected, don't restrict it so much
2025-08-29 17:09:07 +01:00
djc
11793a852b Assigned RUSTSEC-2025-0052 to async-std 2025-08-27 13:36:30 +02:00
Sanpi
6b6d8158ae Add discontinued async-std crate 2025-08-27 13:33:01 +02:00
djc
4f41cf9977 Assigned RUSTSEC-2025-0051 to xcb 2025-08-22 13:20:53 +02:00
En-En
bf013bc589 xcb connect_to_fd* constructors unsound (#2355) 2025-08-22 13:02:49 +02:00
github-actions[bot]
61aac2116c Assigned RUSTSEC-2025-0050 to id-map (#2368) 2025-08-15 20:42:09 +02:00
George Androutsopoulos
13bf15a143 id-map: free uninitialized memory on drop 2025-08-15 19:52:18 +02:00
djc
e8656e02cf Assigned RUSTSEC-2025-0049 to scratchpad 2025-08-14 22:48:29 +02:00
Georgios Androutsopoulos
9b3641d0aa HBOF due to user-defined implementations of scratchpad::Tracking (fix note) 2025-08-14 22:02:40 +02:00
Georgios Androutsopoulos
0dc8063289 HBOF due to user-defined implementations of scratchpad::Tracking (add note) 2025-08-14 22:02:40 +02:00
Georgios Androutsopoulos
1196d728d5 HBOF due to user-defined implementations of scratchpad::Tracking (fix ref) 2025-08-14 22:02:40 +02:00
Georgios Androutsopoulos
34340505ee HBOF due to user-defined implementations of scratchpad::Tracking 2025-08-14 22:02:40 +02:00
djc
5c87b92613 Assigned RUSTSEC-2025-0048 to tsify-next 2025-08-13 16:05:32 +02:00
Theo von Arx
77b281475f Add unmaintained advisory for tsify-next 2025-08-13 16:04:42 +02:00
djc
eadb7bac15 Assigned RUSTSEC-2025-0047 to slab 2025-08-12 11:41:13 +02:00
Motoyuki Kimura
14405bc0b3 Add history of slab's OOB issue 2025-08-12 11:23:49 +02:00
dependabot[bot]
cebfd04415 Bump actions/checkout from 4 to 5
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 5.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v4...v5)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '5'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-08-12 07:53:19 +02:00
Sola
388a3128c3 Fix typo in RUSTSEC-2025-0012 2025-08-06 11:33:04 +02:00
Luke Simmons
c62e71ad8c Update RUSTSEC-2024-0436 to include possible alternative
Update RUSTSEC-2024-0436 to include pastey as an alternative to paste.
2025-07-23 15:03:26 +02:00
djc
babf308081 Assigned RUSTSEC-2025-0046 to wasmtime 2025-07-18 21:48:13 +02:00
Roman Volosatovs
9f011d2bfd wasmtime: fd_renumber panic
Signed-off-by: Roman Volosatovs <rvolosatovs@riseup.net>
2025-07-18 21:26:23 +02:00
djc
b0d34babef Assigned RUSTSEC-2025-0045 to static_cell 2025-07-17 16:38:11 +02:00
ROMemories
0ecf0f6ca3 static_cell: report unsoundness in ConstStaticCell 2025-07-17 16:09:10 +02:00
djc
c67f7726a9 Assigned RUSTSEC-2025-0044 to slice-ring-buffer 2025-07-14 22:21:09 +02:00
George Androutsopoulos
e9fe7f2228 DFs in slice-ring-buffer (#2336) 2025-07-14 22:16:52 +02:00
djc
90cc845377 Assigned RUSTSEC-2025-0043 to matrix-sdk-sqlite 2025-07-11 17:30:12 +02:00
Damir Jelić
4aeb49df4e Add CVE-2025-53549 for matrix-sdk-sqlite 2025-07-11 16:04:51 +02:00
djc
3a1df8e368 Assigned RUSTSEC-2025-0042 to static-alloc 2025-07-11 12:38:44 +02:00
A. Molzer
20c78d241d Advisory for static-alloc 2025-07-11 12:37:31 +02:00
djc
7573f55ba3 Assigned RUSTSEC-2024-0442 to wasmtime-jit-debug 2025-06-17 11:04:25 +02:00
Safe4U
a5f88f0b07 Add advisory for unsound problem in wasmtime_jit_debug (#1999)
Co-authored-by: lihuan <lihuan0530@gmail.com>
2025-06-17 11:02:40 +02:00
Dirkjan Ochtman
02e6496f7c Remove mention of Google Group from CONTRIBUTING 2025-06-16 14:45:11 +02:00
github-actions[bot]
eaef7f63c3 Assigned RUSTSEC-2025-0041 to matrix-sdk-crypto (#2333)
Co-authored-by: djc <158471+djc@users.noreply.github.com>
2025-06-12 11:17:43 +02:00
Damir Jelić
752b7c66e7 Add CVE-2025-48937 to matrix-sdk-crypto (#2332)
Co-authored-by: Denis Kasak <dkasak@termina.org.uk>
2025-06-12 11:16:58 +02:00
djc
a1f651cba8 Assigned RUSTSEC-2025-0040 to users 2025-06-03 13:30:36 +02:00
Daniel Thwaites
0c55633e33 Report incorrect group information in users 2025-06-03 13:29:51 +02:00