Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Will 1.52.0 fix CVE-2021-31162 ? #84847

Closed
zarniwhoop73 opened this issue May 3, 2021 · 2 comments
Closed

Will 1.52.0 fix CVE-2021-31162 ? #84847

zarniwhoop73 opened this issue May 3, 2021 · 2 comments

Comments

@zarniwhoop73
Copy link

#83618 has a related CVE, CVE-2021-31162.

I see that gentoo have work in progress to patch 1.51.0 for this and other recent CVEs, but the description suggests that versions before 1.53.0 are vulnerable. So, will the fix for this be included in 1.52.0 ? If so, you might wish to dispute the CVE, or at least the details. I see that 1.52.0 is due this week, but alpha is 1.54.0, i.e. 1.53.0 has disappeared.

I note that there have been previous 'patch' releases (e.g. for 1.45) and am disappointed that an apparently very important vulnerability has not mentioned similar treatment. It is bad enough that distributions have to rebuild everything which uses rust in case the vulnerable item was pulled in (just like the old "a vulnerable static zlib version was shipped by many packages" problem from years ago), but not having a fixed release makes claims about security look unviable.

Please correct me if I am wrong.

And yes, this is a security issue, but the CVE is already public and rated as Critical, e.g. https://nvd.nist.gov/

@xry111
Copy link
Contributor

xry111 commented May 3, 2021

It's backported into beta as 836fef0.

@jyn514
Copy link
Member

jyn514 commented May 3, 2021

You can tell by looking at the milestones on the PR:
image
(and you can find the PR by looking at the issue:
image)

@jyn514 jyn514 closed this as completed May 3, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants