Skip to content

Add advisory for git2: Remote::list() with an empty list triggers UB - #2888

Merged
djc merged 2 commits into
rustsec:mainfrom
DanielEScherzer:git2-remote-list
Jun 17, 2026
Merged

djc merged 2 commits into
rustsec:mainfrom
DanielEScherzer:git2-remote-list

Conversation

@DanielEScherzer

Copy link
Copy Markdown
Contributor

Affected crate(s)

  • git2

Links to upstream issue(s) or PR(s)

rust-lang/git2-rs#1217, rust-lang/git2-rs#1250

Severity

Low? Potential UB from misuse of an unsafe function

Checklist

  • Advisory filename(s) starts with RUSTSEC-0000-0000 as the ID
  • date field is set to the public disclosure date
  • Contains a concise and descriptive title after advisory metadata
  • Asked maintainer(s) if publishing an advisory is appropriate

@DanielEScherzer

DanielEScherzer commented May 16, 2026 •

Copy link
Copy Markdown
Contributor Author

Date is set as the date of the PR to fix the issue being created

Filed pre-emptively with versions > 0.20.4, will update once a new version has been released

@djc

djc commented May 18, 2026 •

Copy link
Copy Markdown
Member
  • Asked maintainer(s) if publishing an advisory is appropriate

Not seeing a public comment from the maintainer about approval of publishing a RustSec advisory.

@DanielEScherzer

Copy link
Copy Markdown
Contributor Author

@weihanglo thoughts?

@weihanglo weihanglo left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The description is accurate.

@djc
djc merged commit 1916f9e into rustsec:main Jun 17, 2026
1 check passed
@DanielEScherzer
DanielEScherzer deleted the git2-remote-list branch June 17, 2026 17:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants