From ce150ef8cbed58f21f235c267cd5f501ffa56756 Mon Sep 17 00:00:00 2001 From: Nikhil Benesch Date: Tue, 5 Apr 2022 11:24:42 -0400 Subject: [PATCH] RUSTSEC-2022-0012: note that v0.10.0+ is patched (#1220) As far as I can tell, v0.10.0+ was not affected by this bug [0]. The commit which fixes the unsoundness landed in main before v0.10.0 was released. [0]: https://github.com/jorgecarleitao/arrow2/commit/9d4342c5ff2ff1593232373a9998c3da18c7854d --- crates/arrow2/RUSTSEC-2022-0012.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/crates/arrow2/RUSTSEC-2022-0012.md b/crates/arrow2/RUSTSEC-2022-0012.md index 62f9e15..958bc0f 100644 --- a/crates/arrow2/RUSTSEC-2022-0012.md +++ b/crates/arrow2/RUSTSEC-2022-0012.md @@ -7,7 +7,7 @@ url = "https://github.com/jorgecarleitao/arrow2/issues/880" categories = ["memory-corruption"] [versions] -patched = [">= 0.7.1, < 0.8", ">= 0.8.2, < 0.9", ">= 0.9.2, < 0.10"] +patched = [">= 0.7.1, < 0.8", ">= 0.8.2, < 0.9", ">= 0.9.2, < 0.10", ">= 0.10.0"] ``` # Arrow2 allows double free in `safe` code