Commit Graph

1041 Commits

Author SHA1 Message Date
Tony Arcieri
049df72e54 Bump rustsec-admin to v0.3.4 (#695) 2021-01-26 12:50:49 -08:00
Sergey "Shnatsel" Davidoff
773a35e313 Merge pull request #689 from RustSec/assign-ids
Assigned RUSTSEC-2020-0121 to abox
2021-01-25 18:22:34 +01:00
Shnatsel
b24162aeec Assigned RUSTSEC-2020-0121 to abox 2021-01-25 17:21:38 +00:00
Sergey "Shnatsel" Davidoff
9fffafaa84 Merge pull request #688 from JOE1994/0031-abox
abox: AtomicBox<T> implements Send/Sync for any `T: Sized`
2021-01-25 18:21:02 +01:00
JOE1994
d88f06e253 Report 0031-abox to RustSec 2021-01-25 10:44:44 -05:00
Sergey "Shnatsel" Davidoff
2f59446902 Merge pull request #686 from RustSec/assign-ids
Assigned RUSTSEC-2020-0120 to libsbc
2021-01-25 15:42:26 +01:00
Shnatsel
3880134a54 Assigned RUSTSEC-2020-0120 to libsbc 2021-01-25 14:41:19 +00:00
Sergey "Shnatsel" Davidoff
80a200c050 Merge pull request #679 from JOE1994/0027-libsbc
libsbc: Decoder<R> can carry `R: !Send` to other threads
2021-01-25 15:40:45 +01:00
Youngsuk Kim
0850c3b0d3 Clarify description for issue found in 'libsbc' 2021-01-25 09:39:39 -05:00
Sergey "Shnatsel" Davidoff
860dacd16d Merge pull request #684 from RustSec/assign-ids
Assigned RUSTSEC-2020-0119 to ticketed_lock
2021-01-25 14:21:40 +01:00
Shnatsel
99c934de96 Assigned RUSTSEC-2020-0119 to ticketed_lock 2021-01-25 13:20:14 +00:00
Sergey "Shnatsel" Davidoff
e4b62ba529 Merge pull request #678 from JOE1994/0048-ticketed_lock
ticketed_lock: ReadTicket and WriteTicket should only be sendable when T is Send
2021-01-25 14:19:40 +01:00
Sergey "Shnatsel" Davidoff
bf96ab9fd9 Merge pull request #682 from davidkna/patch-1
sys-info: Add patched version for RUSTSEC-2020-0100
2021-01-25 14:19:04 +01:00
David Knaack
99758fa158 Add patched version for RUSTSEC-2020-0100 2021-01-25 13:28:21 +01:00
JOE1994
735a9dbbe2 Report 0027-libsbc to RustSec 2021-01-24 21:52:25 -05:00
JOE1994
a4abf5bb3f Report 0048-ticketed_lock to RustSec 2021-01-24 20:19:27 -05:00
Sergey "Shnatsel" Davidoff
0290f2ba88 Merge pull request #676 from RustSec/assign-ids
Assigned RUSTSEC-2020-0118 to tiny_future
2021-01-25 00:45:28 +01:00
Shnatsel
0aec292a5c Assigned RUSTSEC-2020-0118 to tiny_future 2021-01-24 23:44:45 +00:00
Sergey "Shnatsel" Davidoff
5b856c10b8 Merge pull request #675 from ammaraskar/tiny_future
[patched] Add advisory for data race in tiny_future
2021-01-25 00:44:13 +01:00
Ammar Askar
4bfa224c9f Add advisory for data race in tiny_future 2021-01-24 15:36:47 -08:00
Sergey "Shnatsel" Davidoff
b8c3c5e244 Merge pull request #673 from RustSec/assign-ids
Assigned RUSTSEC-2020-0117 to conqueue
2021-01-24 23:03:55 +01:00
Shnatsel
4350ed71c7 Assigned RUSTSEC-2020-0117 to conqueue 2021-01-24 22:02:11 +00:00
Sergey "Shnatsel" Davidoff
261241340c Merge pull request #672 from JOE1994/0032-conqueue
conqueue: QueueSender's Send trait and Sync trait should have bounds
2021-01-24 23:01:38 +01:00
JOE1994
92a9ea5f21 Report 0032-conqueue to RustSec 2021-01-24 16:13:12 -05:00
Sergey "Shnatsel" Davidoff
f32aab0bba Merge pull request #669 from RustSec/assign-ids
Assigned RUSTSEC-2021-0013 to raw-cpuid
2021-01-24 21:27:26 +01:00
Shnatsel
dd9f177956 Assigned RUSTSEC-2021-0013 to raw-cpuid 2021-01-24 20:26:39 +00:00
Sergey "Shnatsel" Davidoff
b33006702b Merge pull request #614 from niklasf/raw-cpuid
raw-cpuid: Multiple soundness issues
2021-01-24 21:26:11 +01:00
Niklas Fiekas
2e01144dc4 prepare first part of raw-cpuid advisory, add solutions 2021-01-24 21:24:39 +01:00
Sergey "Shnatsel" Davidoff
aba18b27ed Merge pull request #667 from mitsuhiko/feature/add-similar
Add similar suggestion to difference.rs
2021-01-24 20:53:50 +01:00
Armin Ronacher
c0b7f03250 Add similar suggestion to difference.rs 2021-01-24 20:50:18 +01:00
Sergey "Shnatsel" Davidoff
71114d262e Merge pull request #657 from RustSec/assign-ids
Assigned RUSTSEC-2020-0116 to unicycle, RUSTSEC-2021-0012 to cdr
2021-01-24 17:03:46 +01:00
Shnatsel
5b0a58befb Assigned RUSTSEC-2020-0116 to unicycle, RUSTSEC-2021-0012 to cdr 2021-01-24 16:03:19 +00:00
Sergey "Shnatsel" Davidoff
4ef3fb33fb Merge pull request #655 from JOE1994/0041-unicycle
unicycle: PinSlab<T> and Unordered<T, S> need bounds on their Send/Sync traits
2021-01-24 17:02:47 +01:00
Sergey "Shnatsel" Davidoff
2b91d6dd5c Merge pull request #656 from JOE1994/0085-cdr
cdr: Reading uninitialized memory can cause UB (`Deserializer::read_vec`)
2021-01-24 17:02:17 +01:00
JOE1994
d5dac477ee Report 0085-cdr to RustSec 2021-01-24 07:31:17 -05:00
JOE1994
d0b9cd8051 Report 0041-unicycle to RustSec 2021-01-24 07:20:09 -05:00
Sergey "Shnatsel" Davidoff
0a8f5ce4b9 Merge pull request #647 from RustSec/assign-ids
Assigned RUSTSEC-2020-0115 to ruspiro-singleton
2021-01-22 20:28:19 +01:00
Shnatsel
fca5ca1d2b Assigned RUSTSEC-2020-0115 to ruspiro-singleton 2021-01-22 19:27:29 +00:00
Sergey "Shnatsel" Davidoff
877505e85e Merge pull request #646 from ammaraskar/ruspiro-singleton
[patched] Add advisory for data race in ruspiro-singleton
2021-01-22 20:26:54 +01:00
Ammar Askar
f7307c1304 Add advisory for data race in ruspiro-singleton 2021-01-22 11:09:50 -08:00
Sergey "Shnatsel" Davidoff
c6a1282c5f Merge pull request #645 from RustSec/assign-ids
dummy commit to initialize ID assignment race detection
2021-01-22 00:38:49 +01:00
tarcieri
bd83e1ecc2 Assigned 2021-01-21 23:33:06 +00:00
Sergey "Shnatsel" Davidoff
c910443c13 ID assignment action: guard against race conditions (#641)
* ID assignment action: guard against race conditions resulting in duplicate ID assignment

* Add duplicate ID guard file
2021-01-21 15:32:36 -08:00
Sergey "Shnatsel" Davidoff
6ee36b9a18 Delete duplicate advisory for may_queue 2021-01-21 23:44:29 +01:00
Sergey "Shnatsel" Davidoff
b01064fb98 Merge pull request #644 from RustSec/assign-ids
Assigned RUSTSEC-2020-0114 to va-ts
2021-01-21 23:42:16 +01:00
Shnatsel
b72b2c0ad2 Assigned RUSTSEC-2020-0114 to va-ts 2021-01-21 22:41:46 +00:00
Sergey "Shnatsel" Davidoff
0b3a054ef3 Merge pull request #642 from JOE1994/0077-va-ts
va-ts: `Demuxer` can carry non-Send types across thread boundaries
2021-01-21 23:41:19 +01:00
JOE1994
464571fbe1 Report 0077-va-ts to RustSec 2021-01-21 17:21:40 -05:00
Sergey "Shnatsel" Davidoff
9f4be3dd3e Merge pull request #639 from RustSec/rand-more-patched-versions
Update RUSTSEC-2019-0035.md with more patched versions
2021-01-20 20:53:55 +01:00
Sergey "Shnatsel" Davidoff
e084c94822 Update RUSTSEC-2019-0035.md 2021-01-20 20:52:39 +01:00