Skip to content

Commit 35c54a7

Browse files
Merge pull request #6539 from github/oschwald-GHSA-mj73-j457-8x9q
2 parents 71bcc03 + 91938ff commit 35c54a7

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

advisories/github-reviewed/2025/12/GHSA-mj73-j457-8x9q/GHSA-mj73-j457-8x9q.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,15 +1,15 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-mj73-j457-8x9q",
4-
"modified": "2025-12-02T00:29:11Z",
4+
"modified": "2025-12-02T00:29:14Z",
55
"published": "2025-12-02T00:29:11Z",
66
"aliases": [],
77
"summary": "maxminddb's `Reader::open_mmap` unsoundly marks unsafe memmap operation as safe",
88
"details": "maxminddb prior to version 0.27 declared `Reader::open_mmap` as safe despite wrapping an inherently unsafe memmap2 operation with no extra step done to guarantee safety. This could have led to undefined behaviour if the file were to be modified on disk while the memory map was still active.",
99
"severity": [
1010
{
1111
"type": "CVSS_V4",
12-
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"
12+
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N"
1313
}
1414
],
1515
"affected": [

0 commit comments

Comments
 (0)