Bug 2214227 - RUSTSEC-2023-0042: ouroboros is unsound
Summary: RUSTSEC-2023-0042: ouroboros is unsound
Keywords:
Status: CLOSED RAWHIDE
Alias: None
Product: Fedora
Classification: Fedora
Component: mercurial
Version: rawhide
Hardware: Unspecified
OS: Linux
unspecified
medium
Target Milestone: ---
Assignee: Mads Kiilerich
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks: 2214198
TreeView+ depends on / blocked
 
Reported: 2023-06-12 10:09 UTC by Fabio Valentini
Modified: 2023-07-30 17:07 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2023-07-30 17:07:15 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Fabio Valentini 2023-06-12 10:09:31 UTC
c.f. https://rustsec.org/advisories/RUSTSEC-2023-0042.html

The ouroboros crate is affected by soundness issues, which could result in invalid code being generated in future versions of Rust. The upstream project recommends to migrate to the self_cell crate:

https://github.com/joshua-maros/ouroboros/issues/88

Reproducible: Always

Comment 1 Fabio Valentini 2023-07-30 17:07:15 UTC
mercurial has migrated to self_cell and is no longer affected.


Note You need to log in before you can comment on or make changes to this bug.