Closed
Description
If the code that uses libflate panics, it may trigger a use-after-free in libflate code. Since use-after-free usually poses an arbitrary code execution vulnerability, I will relay further details privately to the maintainer.
Code compiled with panic=abort
is not affected. This can be used as a mitigation in the interim.
Metadata
Metadata
Assignees
Labels
No labels