From b9eed83776b4d484b512833a130dce9e9af94ef1 Mon Sep 17 00:00:00 2001 From: Alex Gaynor Date: Sat, 28 Nov 2020 15:43:56 -0500 Subject: [PATCH] Added advisory for pyo3 reference counting issue --- crates/pyo3/RUSTSEC-0000-0000.md | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) create mode 100644 crates/pyo3/RUSTSEC-0000-0000.md diff --git a/crates/pyo3/RUSTSEC-0000-0000.md b/crates/pyo3/RUSTSEC-0000-0000.md new file mode 100644 index 0000000..3973f65 --- /dev/null +++ b/crates/pyo3/RUSTSEC-0000-0000.md @@ -0,0 +1,17 @@ +```toml +[advisory] +id = "RUSTSEC-0000-0000" +package = "pyo3" +date = "2020-11-28" +url = "https://github.com/PyO3/pyo3/pull/1297" +keywords = ["memory-corruption"] + +[versions] +patched = [">= 0.12.4"] +unaffected = ["< 0.12.0"] +``` + +# Reference counting error in `From>` + +A bug in `From>` would lead to an extra reference count decrement, often +leading to use-after-free issues.