Commit fe99e0d
committed
Bump
RUSTSEC-2026-0104 reports a reachable DoS panic in `rustls-webpki`
versions prior to `0.103.13` when parsing a CRL whose
`IssuingDistributionPoint.onlySomeReasons` extension contains a
syntactically valid empty `BIT STRING`. Bumping the pinned version in
both checked-in lock files to `0.103.13` addresses the advisory.
Co-Authored-By: HAL 9000
Signed-off-by: Elias Rohrer <dev@tnull.de>rustls-webpki to patched version in lock files1 parent a8ab194 commit fe99e0d
3 files changed
Lines changed: 5 additions & 5 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
947 | 947 | | |
948 | 948 | | |
949 | 949 | | |
950 | | - | |
| 950 | + | |
951 | 951 | | |
952 | | - | |
| 952 | + | |
953 | 953 | | |
954 | 954 | | |
955 | 955 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
947 | 947 | | |
948 | 948 | | |
949 | 949 | | |
950 | | - | |
| 950 | + | |
951 | 951 | | |
952 | | - | |
| 952 | + | |
953 | 953 | | |
954 | 954 | | |
955 | 955 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
24 | 24 | | |
25 | 25 | | |
26 | 26 | | |
27 | | - | |
| 27 | + | |
28 | 28 | | |
29 | 29 | | |
30 | 30 | | |
| |||
0 commit comments