/
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-qvxr-859j-q25w

Published

Last updated

https://images.chainguard.dev/security/CGA-qvxr-859j-q25w
Package

marzano

RepositoryWolfi
Latest Update
Under investigation
Aliases
  • GHSA-q445-7m23-qrmw

Severity

6.5

Medium

CVSS V3

Summary

openssl's MemBio::get_buf has undefined behavior with empty buffers

Description

Previously, MemBio::get_buf called slice::from_raw_parts with a null-pointer, which violates the functions invariants, leading to undefined behavior. In debug builds this would produce an assertion failure. This is now fixed.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs