Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, an unchecked vsnprintf return in SStream_concat lets a malicious cs_opt_mem.vsnprintf drive SStream’s index negative or past the end, leading to a stack buffer underflow/overflow when the next write occurs. Commit 2c7797182a1618be12017d7d41e0b6581d5d529e fixes the issue.
capstone is not used nor built by the rust package. @pogwuche in more recent updates to rust packaging, the capstone source included with the original rust source, but is removed during the prep stage. Do you know if that is sufficient to prevent reporting false positives?
Yes. If is is removed during the prep stage and the final package doesn’t build or ship capstone, that’s sufficient. we’d set as not affected on our end going forward(if it happens to appear in our manifest).