add hyper uninitialized memory advisory#1232
Conversation
|
Uninit memory turned into references may lead to dangling pointers in practice. I'd bump it from Also I'd like to get sign-off from @seanmonstar so that they don't get a security advisory out of the blue |
|
I am pretty sure the crate never dereferences that uninit pointer. It was unused. But it had a type which indicated it should be non-null. (In theory the compiler might have introduced spurious loads from that pointer, but we have no evidence of that actually happening.) |
|
Alright. Since it's an old issue and is only |
|
Thanks a lot for reporting! |
|
I wouldn't call it a vulnerability myself. The compiler could have done a thing, but it never did. I don't see any reason to warn people, warnings can fatigue. |
That's exactly what the "unsound" category is for, I think. It's informational, not a vulnerability. |
Adds an advisory for the fix in hyperium/hyper#2545.