Skip to content

add advisory for pam-bindings#2771

Open
MartinNowak wants to merge 1 commit into
rustsec:mainfrom
MartinNowak:pam-bindings
Open

add advisory for pam-bindings#2771
MartinNowak wants to merge 1 commit into
rustsec:mainfrom
MartinNowak:pam-bindings

Conversation

@MartinNowak
Copy link
Copy Markdown

@MartinNowak MartinNowak commented Apr 8, 2026

Depeneds on: rustsec/rustsec#1582

Copy link
Copy Markdown
Member

@djc djc left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for reporting! Should address the lint issue.

I've asked the maintainers to confirm they're okay with an advisory in

Comment thread crates/pam-bindings/RUSTSEC-0000-0000.md Outdated
@MartinNowak MartinNowak force-pushed the pam-bindings branch 3 times, most recently from 2661a13 to 0f2af77 Compare April 8, 2026 12:25
@MartinNowak
Copy link
Copy Markdown
Author

Should address the lint issue.

I'm having trouble with the crate name pam-bindings not matching the library name pam 🤔.

@djc
Copy link
Copy Markdown
Member

djc commented Apr 8, 2026

Should address the lint issue.

I'm having trouble with the crate name pam-bindings not matching the library name pam 🤔.

Huh, that's a little annoying. Can you file an issue against the rustsec/rustsec repo?

@MartinNowak
Copy link
Copy Markdown
Author

MartinNowak commented May 5, 2026

I've updated the advisory and commented out the affected function for now to unblock this @djc.

Hopefully the pragmatic approach can be merged rustsec/rustsec#1575 (comment), but that shouldn't block alerting PAM module implementations to check whether they are affected.

Thanksfully one module already implemented a workaround rado0x54/pam-ssh-agent-webauthn#14.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants