Skip to content

Commit 8a41e00

Browse files
committed
Rebase on 2024 Transparency update
I've added Github issues for all the new Chromium issue tracker entries.
1 parent 1bd9859 commit 8a41e00

File tree

1 file changed

+27
-14
lines changed

1 file changed

+27
-14
lines changed

llvm/docs/SecurityTransparencyReports.rst

Lines changed: 27 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -172,10 +172,12 @@ publishing security advisories for those issues at
172172
https://github.com/llvm/llvm-security-repo/security/advisories/.
173173

174174
1. “Unexpected behavior when using LTO and branch-protection together” |br|
175-
Details are available at https://bugs.chromium.org/p/llvm/issues/detail?id=58
175+
Details are available at https://issuetracker.google.com/issues/42410051
176+
archive: https://github.com/llvm/llvm-project/issues/132185
176177
2. “Security weakness in PCS for CMSE”
177178
(`CVE-2024-0151 <https://nvd.nist.gov/vuln/detail/CVE-2024-0151>`_) |br|
178-
Details are available at https://bugs.chromium.org/p/llvm/issues/detail?id=68
179+
Details are available at https://issuetracker.google.com/issues/42410062
180+
archive: https://github.com/llvm/llvm-project/issues/132186
179181
3. “CMSE secure state may leak from stack to floating-point registers”
180182
(`CVE-2024-7883 <https://www.cve.org/cverecord?id=CVE-2024-7883>`_) |br|
181183
Details are available at
@@ -185,9 +187,11 @@ Supply chain security related issues and project services-related issues
185187
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
186188

187189
1. “GitHub User Involved in xz backdoor may have attempted to change to clang in order to help hide the exploit” |br|
188-
Details are available at https://bugs.chromium.org/p/llvm/issues/detail?id=71
190+
Details are available at https://issuetracker.google.com/issues/42410066
191+
archive: https://github.com/llvm/llvm-project/issues/132187
189192
2. “llvmbot account suspended due to supicious login” |br|
190-
Details are available at https://bugs.chromium.org/p/llvm/issues/detail?id=72
193+
Details are available at https://issuetracker.google.com/issues/42410067
194+
archive: https://github.com/llvm/llvm-project/issues/132243
191195
3. “.git Exposure” |br|
192196
GHSA-mr8r-vvrc-w6rq |br|
193197
The .git directory was accessible via web browsers under apt.llvm.org, a site
@@ -224,23 +228,32 @@ Issues deemed to not require coordinated action before disclosing publicly
224228
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
225229

226230
1. “Clang Address Sanitizer gives False Negative for Array Out of Bounds Compiled with Optimization” |br|
227-
Details are available at https://bugs.chromium.org/p/llvm/issues/detail?id=57
231+
Details are available at https://issuetracker.google.com/issues/42410050
232+
archive: https://github.com/llvm/llvm-project/issues/132191
228233
2. “Found exposed .svn folder” |br|
229-
Details are available at https://bugs.chromium.org/p/llvm/issues/detail?id=59
234+
Details are available at https://issuetracker.google.com/issues/42410052
235+
archive: https://github.com/llvm/llvm-project/issues/132192
230236
3. “Arbitrary code execution when combining SafeStack \+ dynamic stack allocations \+ \_\_builtin\_setjmp/longjmp” |br|
231-
Details are available at https://bugs.chromium.org/p/llvm/issues/detail?id=60
237+
Details are available at https://issuetracker.google.com/issues/42410054
238+
archive: https://github.com/llvm/llvm-project/issues/132220
232239
4. “RISC-V: Constants are allocated in writeable .sdata section” |br|
233-
Details are available at https://bugs.chromium.org/p/llvm/issues/detail?id=61
240+
Details are available at https://issuetracker.google.com/issues/42410055
241+
archive: https://github.com/llvm/llvm-project/issues/132223
234242
5. “Manifest File with Out-of-Date Dependencies with CVEs” |br|
235-
Details are available at https://bugs.chromium.org/p/llvm/issues/detail?id=62
243+
Details are available at https://issuetracker.google.com/issues/42410056
244+
archive: https://github.com/llvm/llvm-project/issues/132225
236245
6. “Non-const derived ctor should fail compilation when having a consteval base ctor” |br|
237-
Details are available at https://bugs.chromium.org/p/llvm/issues/detail?id=67
246+
Details are available at https://issuetracker.google.com/issues/42410061
247+
archive: https://github.com/llvm/llvm-project/issues/132226
238248
7. “Wrong assembly code generation. Branching to the corrupted "LR".” |br|
239-
Details are available at https://bugs.chromium.org/p/llvm/issues/detail?id=69
249+
Details are available at https://issuetracker.google.com/issues/42410063
250+
archive: https://github.com/llvm/llvm-project/issues/132229
240251
8. “Security bug report” |br|
241-
Details are available at https://bugs.chromium.org/p/llvm/issues/detail?id=70
252+
Details are available at https://issuetracker.google.com/issues/42410065
253+
archive: https://github.com/llvm/llvm-project/issues/132233
242254
9. “Using ASan with setuid binaries can lead to arbitrary file write and elevation of privileges” |br|
243-
Details are available at https://bugs.chromium.org/p/llvm/issues/detail?id=73
255+
Details are available at https://issuetracker.google.com/issues/42410068
256+
archive: https://github.com/llvm/llvm-project/issues/132235
244257
10. “Interesting bugs for bool variable in clang projects and aarch64 modes outputting inaccurate results.” |br|
245258
GHSA-w7qc-292v-5xh6 |br|
246259
The issue reported is on a source code example having undefined behaviour
@@ -302,4 +315,4 @@ as part of migrating to GitHub's “security advisory”-based reporting:
302315
1. “Test if new draft security advisory gets emailed to LLVM security group” |br|
303316
GHSA-82m9-xvw3-rvpv
304317
2. “Test that a non-admin can create an advisory (no vulnerability).” |br|
305-
GHSA-34gr-6c7h-cc93
318+
GHSA-34gr-6c7h-cc93

0 commit comments

Comments
 (0)