Commit Graph

1031 Commits

Author SHA1 Message Date
Sergey "Shnatsel" Davidoff
860dacd16d Merge pull request #684 from RustSec/assign-ids
Assigned RUSTSEC-2020-0119 to ticketed_lock
2021-01-25 14:21:40 +01:00
Shnatsel
99c934de96 Assigned RUSTSEC-2020-0119 to ticketed_lock 2021-01-25 13:20:14 +00:00
Sergey "Shnatsel" Davidoff
e4b62ba529 Merge pull request #678 from JOE1994/0048-ticketed_lock
ticketed_lock: ReadTicket and WriteTicket should only be sendable when T is Send
2021-01-25 14:19:40 +01:00
Sergey "Shnatsel" Davidoff
bf96ab9fd9 Merge pull request #682 from davidkna/patch-1
sys-info: Add patched version for RUSTSEC-2020-0100
2021-01-25 14:19:04 +01:00
David Knaack
99758fa158 Add patched version for RUSTSEC-2020-0100 2021-01-25 13:28:21 +01:00
JOE1994
a4abf5bb3f Report 0048-ticketed_lock to RustSec 2021-01-24 20:19:27 -05:00
Sergey "Shnatsel" Davidoff
0290f2ba88 Merge pull request #676 from RustSec/assign-ids
Assigned RUSTSEC-2020-0118 to tiny_future
2021-01-25 00:45:28 +01:00
Shnatsel
0aec292a5c Assigned RUSTSEC-2020-0118 to tiny_future 2021-01-24 23:44:45 +00:00
Sergey "Shnatsel" Davidoff
5b856c10b8 Merge pull request #675 from ammaraskar/tiny_future
[patched] Add advisory for data race in tiny_future
2021-01-25 00:44:13 +01:00
Ammar Askar
4bfa224c9f Add advisory for data race in tiny_future 2021-01-24 15:36:47 -08:00
Sergey "Shnatsel" Davidoff
b8c3c5e244 Merge pull request #673 from RustSec/assign-ids
Assigned RUSTSEC-2020-0117 to conqueue
2021-01-24 23:03:55 +01:00
Shnatsel
4350ed71c7 Assigned RUSTSEC-2020-0117 to conqueue 2021-01-24 22:02:11 +00:00
Sergey "Shnatsel" Davidoff
261241340c Merge pull request #672 from JOE1994/0032-conqueue
conqueue: QueueSender's Send trait and Sync trait should have bounds
2021-01-24 23:01:38 +01:00
JOE1994
92a9ea5f21 Report 0032-conqueue to RustSec 2021-01-24 16:13:12 -05:00
Sergey "Shnatsel" Davidoff
f32aab0bba Merge pull request #669 from RustSec/assign-ids
Assigned RUSTSEC-2021-0013 to raw-cpuid
2021-01-24 21:27:26 +01:00
Shnatsel
dd9f177956 Assigned RUSTSEC-2021-0013 to raw-cpuid 2021-01-24 20:26:39 +00:00
Sergey "Shnatsel" Davidoff
b33006702b Merge pull request #614 from niklasf/raw-cpuid
raw-cpuid: Multiple soundness issues
2021-01-24 21:26:11 +01:00
Niklas Fiekas
2e01144dc4 prepare first part of raw-cpuid advisory, add solutions 2021-01-24 21:24:39 +01:00
Sergey "Shnatsel" Davidoff
aba18b27ed Merge pull request #667 from mitsuhiko/feature/add-similar
Add similar suggestion to difference.rs
2021-01-24 20:53:50 +01:00
Armin Ronacher
c0b7f03250 Add similar suggestion to difference.rs 2021-01-24 20:50:18 +01:00
Sergey "Shnatsel" Davidoff
71114d262e Merge pull request #657 from RustSec/assign-ids
Assigned RUSTSEC-2020-0116 to unicycle, RUSTSEC-2021-0012 to cdr
2021-01-24 17:03:46 +01:00
Shnatsel
5b0a58befb Assigned RUSTSEC-2020-0116 to unicycle, RUSTSEC-2021-0012 to cdr 2021-01-24 16:03:19 +00:00
Sergey "Shnatsel" Davidoff
4ef3fb33fb Merge pull request #655 from JOE1994/0041-unicycle
unicycle: PinSlab<T> and Unordered<T, S> need bounds on their Send/Sync traits
2021-01-24 17:02:47 +01:00
Sergey "Shnatsel" Davidoff
2b91d6dd5c Merge pull request #656 from JOE1994/0085-cdr
cdr: Reading uninitialized memory can cause UB (`Deserializer::read_vec`)
2021-01-24 17:02:17 +01:00
JOE1994
d5dac477ee Report 0085-cdr to RustSec 2021-01-24 07:31:17 -05:00
JOE1994
d0b9cd8051 Report 0041-unicycle to RustSec 2021-01-24 07:20:09 -05:00
Sergey "Shnatsel" Davidoff
0a8f5ce4b9 Merge pull request #647 from RustSec/assign-ids
Assigned RUSTSEC-2020-0115 to ruspiro-singleton
2021-01-22 20:28:19 +01:00
Shnatsel
fca5ca1d2b Assigned RUSTSEC-2020-0115 to ruspiro-singleton 2021-01-22 19:27:29 +00:00
Sergey "Shnatsel" Davidoff
877505e85e Merge pull request #646 from ammaraskar/ruspiro-singleton
[patched] Add advisory for data race in ruspiro-singleton
2021-01-22 20:26:54 +01:00
Ammar Askar
f7307c1304 Add advisory for data race in ruspiro-singleton 2021-01-22 11:09:50 -08:00
Sergey "Shnatsel" Davidoff
c6a1282c5f Merge pull request #645 from RustSec/assign-ids
dummy commit to initialize ID assignment race detection
2021-01-22 00:38:49 +01:00
tarcieri
bd83e1ecc2 Assigned 2021-01-21 23:33:06 +00:00
Sergey "Shnatsel" Davidoff
c910443c13 ID assignment action: guard against race conditions (#641)
* ID assignment action: guard against race conditions resulting in duplicate ID assignment

* Add duplicate ID guard file
2021-01-21 15:32:36 -08:00
Sergey "Shnatsel" Davidoff
6ee36b9a18 Delete duplicate advisory for may_queue 2021-01-21 23:44:29 +01:00
Sergey "Shnatsel" Davidoff
b01064fb98 Merge pull request #644 from RustSec/assign-ids
Assigned RUSTSEC-2020-0114 to va-ts
2021-01-21 23:42:16 +01:00
Shnatsel
b72b2c0ad2 Assigned RUSTSEC-2020-0114 to va-ts 2021-01-21 22:41:46 +00:00
Sergey "Shnatsel" Davidoff
0b3a054ef3 Merge pull request #642 from JOE1994/0077-va-ts
va-ts: `Demuxer` can carry non-Send types across thread boundaries
2021-01-21 23:41:19 +01:00
JOE1994
464571fbe1 Report 0077-va-ts to RustSec 2021-01-21 17:21:40 -05:00
Sergey "Shnatsel" Davidoff
9f4be3dd3e Merge pull request #639 from RustSec/rand-more-patched-versions
Update RUSTSEC-2019-0035.md with more patched versions
2021-01-20 20:53:55 +01:00
Sergey "Shnatsel" Davidoff
e084c94822 Update RUSTSEC-2019-0035.md 2021-01-20 20:52:39 +01:00
Sergey "Shnatsel" Davidoff
9c7561051d Merge pull request #637 from RustSec/assign-ids
Assigned RUSTSEC-2020-0113 to atomic-option
2021-01-20 20:49:48 +01:00
Shnatsel
21eb4cbc87 Assigned RUSTSEC-2020-0113 to atomic-option 2021-01-20 19:47:43 +00:00
Sergey "Shnatsel" Davidoff
c49be99884 Merge pull request #588 from JOE1994/atomic-option
unconditional Sync impl of `AtomicOption<T>` allows UB
2021-01-20 20:47:06 +01:00
Sergey "Shnatsel" Davidoff
057acf9d06 Merge pull request #635 from RustSec/assign-ids
Assigned RUSTSEC-2021-0011 to fil-ocl
2021-01-20 20:39:08 +01:00
Shnatsel
ba5918eaf9 Assigned RUSTSEC-2021-0011 to fil-ocl 2021-01-20 19:38:26 +00:00
Sergey "Shnatsel" Davidoff
004b3a9df5 Merge pull request #587 from ammaraskar/ocl
Add advisory for double-free in fil-ocl
2021-01-20 20:37:54 +01:00
Sergey "Shnatsel" Davidoff
b37e58bac3 Fix consistency: remove duplicated advisory for buttplug crate 2021-01-20 20:34:23 +01:00
Sergey "Shnatsel" Davidoff
6280792aa7 Fix consistency: rename duplicated RUSTSEC-2020-0110 to RUSTSEC-2020-0112 2021-01-20 20:33:35 +01:00
Sergey "Shnatsel" Davidoff
dfaa65a23e Merge pull request #633 from RustSec/assign-ids
Assigned RUSTSEC-2020-0111 to may_queue
2021-01-20 20:29:40 +01:00
Sergey "Shnatsel" Davidoff
84badb657b Merge pull request #632 from RustSec/assign-ids
Assigned RUSTSEC-2020-0107 to hashconsing, RUSTSEC-2020-0108 to eventio, RUSTSEC-2020-0109 to stderr, RUSTSEC-2020-0110 to may_queue, RUSTSEC-2020-0111 to buttplug
2021-01-20 20:29:24 +01:00