DirectorySecurity Advisories
Sign In
Security Advisories

CGA-wc5p-vj8w-jm26

Published

Last updated

https://images.chainguard.dev/security/CGA-wc5p-vj8w-jm26
Package

zed

Latest Update
Fixed
Fixed Version

0.146.3-r0

Aliases
  • GHSA-q445-7m23-qrmw

Severity

6.5

Medium

CVSS V3

Summary

openssl's MemBio::get_buf has undefined behavior with empty buffers

Description

Previously, MemBio::get_buf called slice::from_raw_parts with a null-pointer, which violates the functions invariants, leading to undefined behavior. In debug builds this would produce an assertion failure. This is now fixed.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images