|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2024-32650: flake-pilot: rust-rustls: Infinite loop in rustls:conn:ConnectionCommon:complete_io() with proper client input | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | Carlos López <carlos.lopez> |
| Component: | Incidents | Assignee: | Marcus Schäfer <marcus.schaefer> |
| Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
| Severity: | Normal | ||
| Priority: | P3 - Medium | CC: | carlos.lopez, kvanderveer, marcus.schaefer |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | Other | ||
| URL: | https://smash.suse.de/issue/402742/ | ||
| Whiteboard: | CVSSv3.1:SUSE:CVE-2024-32650:7.5:(AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) | ||
| Found By: | --- | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
| Bug Depends on: | |||
| Bug Blocks: | 1223211 | ||
|
Description
Carlos López
2024-04-22 11:25:37 UTC
Thanks, it seems the mentioned versions are not yet available in the crate index e.g failed to select a version for the requirement `rustls = "^0.21.21"` I guess a little bit of waiting is needed prior the vendor tarball will pick up the fix Since this is not fixable in the code Marcus wrote, could the security team advise on how to take care of this? >Since this is not fixable
I rechecked today and the crate index has changed with an update rustls variant.
I will submit a package
created request id 1179039 This is an autogenerated message for OBS integration: This bug (1223217) was mentioned in https://build.opensuse.org/request/show/1179039 Factory / flake-pilot submission to TW done |