@@ -172,10 +172,12 @@ publishing security advisories for those issues at
172172https://github.com/llvm/llvm-security-repo/security/advisories/.
173173
1741741. “Unexpected behavior when using LTO and branch-protection together” |br |
175- Details are available at https://bugs.chromium.org/p/llvm/issues/detail?id=58
175+ Details are available at https://issuetracker.google.com/issues/42410051
176+ archive: https://github.com/llvm/llvm-project/issues/132185
1761772. “Security weakness in PCS for CMSE”
177178 (`CVE-2024-0151 <https://nvd.nist.gov/vuln/detail/CVE-2024-0151 >`_) |br |
178- Details are available at https://bugs.chromium.org/p/llvm/issues/detail?id=68
179+ Details are available at https://issuetracker.google.com/issues/42410062
180+ archive: https://github.com/llvm/llvm-project/issues/132186
1791813. “CMSE secure state may leak from stack to floating-point registers”
180182 (`CVE-2024-7883 <https://www.cve.org/cverecord?id=CVE-2024-7883 >`_) |br |
181183 Details are available at
@@ -185,9 +187,11 @@ Supply chain security related issues and project services-related issues
185187^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
186188
1871891. “GitHub User Involved in xz backdoor may have attempted to change to clang in order to help hide the exploit” |br |
188- Details are available at https://bugs.chromium.org/p/llvm/issues/detail?id=71
190+ Details are available at https://issuetracker.google.com/issues/42410066
191+ archive: https://github.com/llvm/llvm-project/issues/132187
1891922. “llvmbot account suspended due to supicious login” |br |
190- Details are available at https://bugs.chromium.org/p/llvm/issues/detail?id=72
193+ Details are available at https://issuetracker.google.com/issues/42410067
194+ archive: https://github.com/llvm/llvm-project/issues/132243
1911953. “.git Exposure” |br |
192196 GHSA-mr8r-vvrc-w6rq |br |
193197 The .git directory was accessible via web browsers under apt.llvm.org, a site
@@ -224,23 +228,32 @@ Issues deemed to not require coordinated action before disclosing publicly
224228^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
225229
2262301. “Clang Address Sanitizer gives False Negative for Array Out of Bounds Compiled with Optimization” |br |
227- Details are available at https://bugs.chromium.org/p/llvm/issues/detail?id=57
231+ Details are available at https://issuetracker.google.com/issues/42410050
232+ archive: https://github.com/llvm/llvm-project/issues/132191
2282332. “Found exposed .svn folder” |br |
229- Details are available at https://bugs.chromium.org/p/llvm/issues/detail?id=59
234+ Details are available at https://issuetracker.google.com/issues/42410052
235+ archive: https://github.com/llvm/llvm-project/issues/132192
2302363. “Arbitrary code execution when combining SafeStack \+ dynamic stack allocations \+ \_\_ builtin\_ setjmp/longjmp” |br |
231- Details are available at https://bugs.chromium.org/p/llvm/issues/detail?id=60
237+ Details are available at https://issuetracker.google.com/issues/42410054
238+ archive: https://github.com/llvm/llvm-project/issues/132220
2322394. “RISC-V: Constants are allocated in writeable .sdata section” |br |
233- Details are available at https://bugs.chromium.org/p/llvm/issues/detail?id=61
240+ Details are available at https://issuetracker.google.com/issues/42410055
241+ archive: https://github.com/llvm/llvm-project/issues/132223
2342425. “Manifest File with Out-of-Date Dependencies with CVEs” |br |
235- Details are available at https://bugs.chromium.org/p/llvm/issues/detail?id=62
243+ Details are available at https://issuetracker.google.com/issues/42410056
244+ archive: https://github.com/llvm/llvm-project/issues/132225
2362456. “Non-const derived ctor should fail compilation when having a consteval base ctor” |br |
237- Details are available at https://bugs.chromium.org/p/llvm/issues/detail?id=67
246+ Details are available at https://issuetracker.google.com/issues/42410061
247+ archive: https://github.com/llvm/llvm-project/issues/132226
2382487. “Wrong assembly code generation. Branching to the corrupted "LR".” |br |
239- Details are available at https://bugs.chromium.org/p/llvm/issues/detail?id=69
249+ Details are available at https://issuetracker.google.com/issues/42410063
250+ archive: https://github.com/llvm/llvm-project/issues/132229
2402518. “Security bug report” |br |
241- Details are available at https://bugs.chromium.org/p/llvm/issues/detail?id=70
252+ Details are available at https://issuetracker.google.com/issues/42410065
253+ archive: https://github.com/llvm/llvm-project/issues/132233
2422549. “Using ASan with setuid binaries can lead to arbitrary file write and elevation of privileges” |br |
243- Details are available at https://bugs.chromium.org/p/llvm/issues/detail?id=73
255+ Details are available at https://issuetracker.google.com/issues/42410068
256+ archive: https://github.com/llvm/llvm-project/issues/132235
24425710. “Interesting bugs for bool variable in clang projects and aarch64 modes outputting inaccurate results.” |br |
245258 GHSA-w7qc-292v-5xh6 |br |
246259 The issue reported is on a source code example having undefined behaviour
@@ -302,4 +315,4 @@ as part of migrating to GitHub's “security advisory”-based reporting:
3023151. “Test if new draft security advisory gets emailed to LLVM security group” |br |
303316 GHSA-82m9-xvw3-rvpv
3043172. “Test that a non-admin can create an advisory (no vulnerability).” |br |
305- GHSA-34gr-6c7h-cc93
318+ GHSA-34gr-6c7h-cc93
0 commit comments