Skip to content

[GHSA-p423-j2cm-9vmq] Cryptography vulnerable to buffer overflow if non-contiguous buffers were passed to APIs - #10209

Open
ranjiGT wants to merge 1 commit into
ranjiGT/advisory-improvement-10209from
ranjiGT-GHSA-p423-j2cm-9vmq
Open

ranjiGT wants to merge 1 commit into
ranjiGT/advisory-improvement-10209from
ranjiGT-GHSA-p423-j2cm-9vmq

Conversation

@ranjiGT

@ranjiGT ranjiGT commented Oct 7, 2026 •

Copy link
Copy Markdown

Updates

  • References

Comments
Adds upstream references for the vulnerability fix.

The commit c09d38ae52de7d95fe683b7a7c496f5751616f27 introduces contiguous-buffer enforcement, while the 46.0.7 release commit 622d672e429a7cff836a23c5903683dbec1901f5 contains the corresponding fix on the 46.0.x release branch.

@github

github commented Oct 7, 2026

Copy link
Copy Markdown
Collaborator

Hi there @alex! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository.

This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory

Copilot AI balanced review requested due to automatic review settings October 7, 2026 17:28
@github-actions
github-actions Bot changed the base branch from main to ranjiGT/advisory-improvement-10209 October 7, 2026 17:29

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

Both referenced commits exist and correspond to the vulnerability fix described.

0 open findings

What changed in this PR

Adds verified upstream fix references for the cryptography buffer-overflow advisory.

Changes:

  • Links the primary contiguous-buffer enforcement commit.
  • Links the corresponding 46.0.7 release commit.
File Description
GHSA-p423-j2cm-9vmq.json Adds two upstream commit references.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants