Skip to content

Conversation

@jasnow
Copy link
Contributor

@jasnow jasnow commented Jan 23, 2026

GHSA SYNC: 1 modified and 1 brand new advisory

to apply a patch to fix this issue.

- Text (not a link)
- https://github.com/user-attachments/files/19619499/mruby_crash.txt
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please avoid putting non-link URLs into advisories.

cvss_v3: 5.5
cvss_v4: 4.4
patched_versions:
- ">= 3.5.0"
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't know how I feel about listing a version that has not been released yet? How is this useful to users? Perhaps it would be more accurate to omit patched_versions: until 3.5.0 has been released.

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/27LUWREIFTP3MQAW7QE4PJM4DPAQJWXF
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XYDHPHEZI7OQXTQKTDZHGZNPIJH7ZV5N
- https://security.netapp.com/advisory/ntap-20241011-0007
- https://github.com/advisories/GHSA-63cq-cj6g-qfr2
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could you extract the changes to rubies/ruby/CVE-2024-27282.yml into a separate PR so it's not held up by questions about the other advisories?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants