Skip to content

Add advisory for git2: Remote::list() with an empty list triggers UB#2888

Open
DanielEScherzer wants to merge 1 commit into
rustsec:mainfrom
DanielEScherzer:git2-remote-list
Open

Add advisory for git2: Remote::list() with an empty list triggers UB#2888
DanielEScherzer wants to merge 1 commit into
rustsec:mainfrom
DanielEScherzer:git2-remote-list

Conversation

@DanielEScherzer
Copy link
Copy Markdown
Contributor

Affected crate(s)

  • git2

Links to upstream issue(s) or PR(s)

rust-lang/git2-rs#1217, rust-lang/git2-rs#1250

Severity

Low? Potential UB from misuse of an unsafe function

Checklist

  • Advisory filename(s) starts with RUSTSEC-0000-0000 as the ID
  • date field is set to the public disclosure date
  • Contains a concise and descriptive title after advisory metadata
  • Asked maintainer(s) if publishing an advisory is appropriate

@DanielEScherzer
Copy link
Copy Markdown
Contributor Author

DanielEScherzer commented May 16, 2026

Date is set as the date of the PR to fix the issue being created

Filed pre-emptively with versions > 0.20.4, will update once a new version has been released

@djc
Copy link
Copy Markdown
Member

djc commented May 18, 2026

  • Asked maintainer(s) if publishing an advisory is appropriate

Not seeing a public comment from the maintainer about approval of publishing a RustSec advisory.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants