You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Code generated by flatbuffers' compiler is unsafe but not marked as such.
See google/flatbuffers#6627 for details.
For example, if generated code is used to decode malformed or untrusted input,
undefined behavior (and thus security vulnerabilities) is possible even without
the use of the unsafe keyword, violating the the meaning of "safe" code;
All users that use generated code by flatbuffers compiler are recommended to:
not expose flatbuffer generated code as part of their public APIs
audit their code and look for any usage of follow, push, or any method that uses them
(e.g. self_follow).
Carefuly go through the crates' documentation to understand which "safe" APIs are not
intended to be used.
flatbuffers
2.1.2
>=22.9.29
Code generated by flatbuffers' compiler is
unsafe
but not marked as such.See google/flatbuffers#6627 for details.
For example, if generated code is used to decode malformed or untrusted input,
undefined behavior (and thus security vulnerabilities) is possible even without
the use of the
unsafe
keyword, violating the the meaning of "safe" code;All users that use generated code by
flatbuffers
compiler are recommended to:follow
,push
, or any method that uses them(e.g.
self_follow
).intended to be used.
See advisory page for additional details.
The text was updated successfully, but these errors were encountered: