Skip to content

Commit

Permalink
Assign RUSTSEC-2020-0004 to lucet-runtime-internals
Browse files Browse the repository at this point in the history
Original PR: #229
  • Loading branch information
tarcieri committed Jan 27, 2020
1 parent 723abd4 commit d8e872f
Showing 1 changed file with 1 addition and 8 deletions.
Original file line number Diff line number Diff line change
@@ -1,12 +1,8 @@
[advisory]
id = "RUSTSEC-0000-0000"

id = "RUSTSEC-2020-0004"
package = "lucet-runtime-internals"

date = "2020-01-24"

title = "sigstack allocation bug can cause memory corruption or leak"

description = """
An embedding using affected versions of lucet-runtime configured to use
non-default Wasm globals sizes of more than 4KiB, or compiled in debug mode
Expand All @@ -16,9 +12,6 @@ guest programs or cause corruption of guest program memory.
This flaw was resolved by correcting the sigstack allocation logic.
"""

patched_versions = ["< 0.5.0, >= 0.4.3", ">= 0.5.1"]

url = "https://github.com/bytecodealliance/lucet/pull/401"

categories = ["memory-corruption", "memory-exposure"]

0 comments on commit d8e872f

Please sign in to comment.