• Bug#1101334: Mimalloc < v0.1.39 Can Allocate Memory with Bad Alignment

    From Jonas Smedegaard@21:1/5 to All on Tue Mar 25 23:00:01 2025
    Source: rust-mimalloc
    Version: 0.1.29-1
    Severity: serious
    Tags: security upstream
    X-Debbugs-Cc: Debian Security Team <[email protected]>

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    Rust crate mimalloc lower than 0.1.39 is considered unsound and has
    been pulled upstream: https://rustsec.org/advisories/RUSTSEC-2022-0094

    - Jonas

    - -- System Information:
    Debian Release: trixie/sid
    APT prefers buildd-unstable
    APT policy: (500, 'buildd-unstable'), (500, 'unstable'), (1, 'buildd-experimental'), (1, 'experimental')
    Architecture: amd64 (x86_64)

    Kernel: Linux 6.9.10-amd64 (SMP w/8 CPU threads; PREEMPT)
    Locale: LANG=da_DK.UTF-8, LC_CTYPE=da_DK.UTF-8 (charmap=UTF-8), LANGUAGE not set
    Shell: /bin/sh linked to /usr/bin/dash
    Init: systemd (via /run/systemd/system)
    LSM: AppArmor: enabled


    -----BEGIN PGP SIGNATURE-----

    wsG7BAEBCgBvBYJn4yVOCRAsfDFGwaABIUcUAAAAAAAeACBzYWx0QG5vdGF0aW9u cy5zZXF1b2lhLXBncC5vcmeN4AfmGdADMvM6X+zHu3htPgIPJ4d6pXmtim6ijtjA kRYhBJ/j6cNmkaaf9TzGhCx8MUbBoAEhAABAgA/9H/4gvaXCmuxAsAoG2zUdo+Tx HwtuKDF1JIW31vLDrAmjodfkINf0rUcI8xIwMqKbsR6D6uuV9A0feCMSHazeHRQc 1uhYVH/VH9XOUMvgNFP06xYeLSSOUeWfgw0oiWD9S2y1WFjvYI3a2F0ekYb+XWsL Kd9m/U/7LKnK0sybUAFYXdnmPDM8/OegDPsqXZgUSArv7We/mbA4NvSbYY39ec9X TYICp+mBBRqB1RE4RRdffL6czzAfDqNMfMS5KVxiJb3DTD8S3hc7mhj0gq/M0ivo 8Z2vmhrM+63f0d2Ai7arR/OkPa/P49GDxgS5xQlvvUbs7BjZSk6qKa/mYF5QmG0I RZqxWYyru5GE1abA6zPaXHHvBCxV2Ne/8V2TPaN+C8XNKrKeYZQHvPey0ZLsXXyk 3/S5QjF838s7z9c+G/NmIEXsc2rU6Z7lbdJeZLbrQtpcdMKb+AvfzRFfOoqfXuv6 aSAzZFKOmtp/FPggT6V9Wd8Ja/SuYnfibM4LRbgzWnRnET/kBYZrG1IVAq0NI81a 4Bk/upGOR1wEFxHKNJg0GnxMXnGfxJ0I2MCIZzzm3olRL4cWRDMecK8/Q6QcIlAX u7pBo6blzqEdfEdARAXa5s7BkuwjL0600PTuqph8otNVz5NmZfYZnWTJKk5cTjps Z0t/5RQelGw46Ip346s=
    =akPg
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Debian Bug Tracking System@21:1/5 to All on Wed Mar 26 10:20:01 2025
    This is a multi-part message in MIME format...

    Your message dated Wed, 26 Mar 2025 09:09:10 +0000
    with message-id <[email protected]>
    and subject line Bug#1101334: fixed in rust-mimalloc 0.1.44-1
    has caused the Debian Bug report #1101334,
    regarding Mimalloc < v0.1.39 Can Allocate Memory with Bad Alignment
    to be marked as done.

    This means that you claim that the problem has been dealt with.
    If this is not the case it is now your responsibility to reopen the
    Bug report if necessary, and/or fix the problem forthwith.

    (NB: If you are a system administrator and have no idea what this
    message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact [email protected]
    immediately.)


    --
    1101334: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1101334
    Debian Bug Tracking System
    Contact [email protected] with problems

    Received: (at submit) by bugs.debian.org; 25 Mar 2025 21:51:22 +0000 X-Spam-Checker-Version: SpamAssassin 3.4.6-bugs.debian.org_2005_01_02
    (2021-04-09) on buxtehude.debian.org
    X-Spam-Level:
    X-Spam-Status: No, score=-12.9 required=4.0 tests=BAYES_00,FOURLA,
    FVGT_m_MULTI_ODD,PGPSIGNATURE,SPF_HELO_PASS,SPF_PASS,XMAILER_REPORTBUG
    autolearn=ham autolearn_force=no
    version=3.4.6-bugs.debian.org_2005_01_02
    X-Spam-Bayes: score:0.0000 Tokens: new, 88; hammy, 150; neutral, 88; spammy,
    0. spammytokens: hammytokens:0.000-+--XDebbugsCc,
    0.000-+--X-Debbugs-Cc, 0.000-+--trixie, 0.000-+--sha512,
    0.000-+--SHA512
    Return-path: <[email protected]>
    Received: from graograman.jones.dk ([87.104.249.100]:37514 helo=xayide.jones.dk)
    by buxtehude.debian.org with utf8esmtps (TLS1.3:ECDHE_X25519__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
    (Exim 4.94.2)
    (envelope-from <[email protected]