mirror of
https://github.com/OMGeeky/advisory-db.git
synced 2025-12-30 08:13:58 +01:00
Merge pull request #229 from jfoote/master
Add lucet-runtime-internals sigstack allocation vuln advisory
This commit is contained in:
24
crates/lucet-runtime-internals/RUSTSEC-0000-0000.toml
Normal file
24
crates/lucet-runtime-internals/RUSTSEC-0000-0000.toml
Normal file
@@ -0,0 +1,24 @@
|
||||
[advisory]
|
||||
id = "RUSTSEC-0000-0000"
|
||||
|
||||
package = "lucet-runtime-internals"
|
||||
|
||||
date = "2020-01-24"
|
||||
|
||||
title = "sigstack allocation bug can cause memory corruption or leak"
|
||||
|
||||
description = """
|
||||
An embedding using affected versions of lucet-runtime configured to use
|
||||
non-default Wasm globals sizes of more than 4KiB, or compiled in debug mode
|
||||
without optimizations, could leak data from the signal handler stack to guest
|
||||
programs. This can potentially cause data from the embedding host to leak to
|
||||
guest programs or cause corruption of guest program memory.
|
||||
|
||||
This flaw was resolved by correcting the sigstack allocation logic.
|
||||
"""
|
||||
|
||||
patched_versions = ["< 0.5.0, >= 0.4.3", ">= 0.5.1"]
|
||||
|
||||
url = "https://github.com/bytecodealliance/lucet/pull/401"
|
||||
|
||||
categories = ["memory-corruption", "memory-exposure"]
|
||||
Reference in New Issue
Block a user