Skip to content

Add advisory for git2: buffer-created BlameHunk leads to null pointers#2889

Open
DanielEScherzer wants to merge 1 commit into
rustsec:mainfrom
DanielEScherzer:git2-buffer-blamehunk
Open

Add advisory for git2: buffer-created BlameHunk leads to null pointers#2889
DanielEScherzer wants to merge 1 commit into
rustsec:mainfrom
DanielEScherzer:git2-buffer-blamehunk

Conversation

@DanielEScherzer
Copy link
Copy Markdown
Contributor

Affected crate(s)

  • git2

Links to upstream issue(s) or PR(s)

rust-lang/git2-rs#1253, rust-lang/git2-rs#1254

Severity

Low? Null pointer derefs

Checklist

  • Advisory filename(s) starts with RUSTSEC-0000-0000 as the ID
  • date field is set to the public disclosure date
  • Contains a concise and descriptive title after advisory metadata
  • Asked maintainer(s) if publishing an advisory is appropriate

@DanielEScherzer
Copy link
Copy Markdown
Contributor Author

DanielEScherzer commented May 16, 2026

Date is set as the date of the PR to fix the issue being created

Filed pre-emptively with versions > 0.20.4, will update once a new version has been released

@djc
Copy link
Copy Markdown
Member

djc commented May 18, 2026

[ ] Asked maintainer(s) if publishing an advisory is appropriate

Please get a maintainer to commit somewhere public.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants