Repository navigation
[GHSA-p423-j2cm-9vmq] Cryptography vulnerable to buffer overflow if non-contiguous buffers were passed to APIs - #10209
Conversation
|
Hi there @alex! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository. This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory |
There was a problem hiding this comment.
🟢 Approval recommended
Both referenced commits exist and correspond to the vulnerability fix described.
0 open findings
What changed in this PR
Adds verified upstream fix references for the cryptography buffer-overflow advisory.
Changes:
- Links the primary contiguous-buffer enforcement commit.
- Links the corresponding 46.0.7 release commit.
| File | Description |
|---|---|
GHSA-p423-j2cm-9vmq.json |
Adds two upstream commit references. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Updates
Comments
Adds upstream references for the vulnerability fix.
The commit
c09d38ae52de7d95fe683b7a7c496f5751616f27introduces contiguous-buffer enforcement, while the46.0.7release commit622d672e429a7cff836a23c5903683dbec1901f5contains the corresponding fix on the46.0.xrelease branch.