Your message dated Wed, 28 Feb 2024 23:27:20 +0100
with message-id <[email protected]>
and subject line Re: Processed: retitle 1061577 to rust-io: RUSTSEC-2020-0021: 
CVE-2020-35876: use-after-free buffer access when a future is leaked
has caused the Debian Bug report #1061577,
regarding rust-io: RUSTSEC-2020-0021: CVE-2020-35876: use-after-free buffer 
access when a future is leaked
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1061577: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1061577
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: rust-rio
Severity: important
X-Debbugs-Cc: [email protected]

Dear Maintainer,

https://rustsec.org/advisories/RUSTSEC-2020-0021.html

Description

When a rio::Completion is leaked, its drop code will not run.
The drop code is responsible for waiting until the kernel
completes the I/O operation into, or out of, the buffer
borrowed by rio::Completion. Leaking the struct will allow one
to access and/or drop the buffer, which can lead to a
use-after-free, data races or leaking secrets.


-- System Information:
Debian Release: trixie/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (500, 'testing')
Architecture: amd64 (x86_64)

Kernel: Linux 6.6.11-amd64 (SMP w/8 CPU threads; PREEMPT)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), 
LANGUAGE=en_US:en
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

--- End Message ---
--- Begin Message ---
Quoting Debian Bug Tracking System (2024-01-27 09:42:03)
> Processing commands for [email protected]:
> 
> > retitle 1061577 rust-io: RUSTSEC-2020-0021: CVE-2020-35876: use-after-free 
> > buffer access when a future is leaked
> Bug #1061577 [src:rust-rio] rust-rio: use-after-free buffer access when a 
> future is leaked
> Changed Bug title to 'rust-io: RUSTSEC-2020-0021: CVE-2020-35876: 
> use-after-free buffer access when a future is leaked' from 'rust-rio: 
> use-after-free buffer access when a future is leaked'.
> > thanks
> Stopping processing here.

The Debian source package src:rust-rio does *not* contain the Rust crate
rio.  That Rust crate originates from Github repository "sacejam/rio",
whereas the Debian package originates from different Github repository
"oxigrah/rio" which contains Rust crates rio_api, rio_turtle and
rio_xml.

Closing as a non-bug.

 - Jonas

-- 
 * Jonas Smedegaard - idealist & Internet-arkitekt
 * Tlf.: +45 40843136  Website: http://dr.jones.dk/
 * Sponsorship: https://ko-fi.com/drjones

 [x] quote me freely  [ ] ask before reusing  [ ] keep private

Attachment: signature.asc
Description: signature


--- End Message ---

Reply via email to