From nobody Thu Mar 05 17:49:51 2026 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4fRcW63gJNz6TQ37 for ; Thu, 05 Mar 2026 17:49:54 +0000 (UTC) (envelope-from shawn.webb@hardenedbsd.org) Received: from mail-ot1-x32b.google.com (mail-ot1-x32b.google.com [IPv6:2607:f8b0:4864:20::32b]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (2048 bits) client-digest SHA256) (Client CN "smtp.gmail.com", Issuer "WR4" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4fRcW56dHCz3vSq for ; Thu, 05 Mar 2026 17:49:53 +0000 (UTC) (envelope-from shawn.webb@hardenedbsd.org) Authentication-Results: mx1.freebsd.org; none Received: by mail-ot1-x32b.google.com with SMTP id 46e09a7af769-7d4b9c839b1so4357056a34.1 for ; Thu, 05 Mar 2026 09:49:53 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hardenedbsd.org; s=google; t=1772732992; x=1773337792; darn=freebsd.org; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:from:to:cc:subject:date:message-id:reply-to; bh=ZMBnwFdtbwEV59MpPwBswm8MRP35o4wwDus6WFw1l3k=; b=LUbbfNyuDGFYRmPwB5pQGDrWmYYYuc2YYhp+9oH1nKKffhF6ER1eaZ0/6dvL/nhZDi MVM1jAIYZWCKRHHd2Jy7mMkoI8bieHhan9kDClMviL6fv5i9S/1PWc+q8Y0h4UjVWXRD HnSY0Yk9tJj47Q52jnWIynygMglRzEz7FBLUUzURKM7qIEZeJgo2kHc0VH8IuXFdIdv4 O0hCpkOzj9iDuvix+Bi5RKmlR1dOW6N4KjuLUjwLbZC8jjBooQWc6ltE/Jm0CT8IkCxI TaHBeYmQy/YK7tRxnI00Y6GZ33yTxAuZlg3hTz2RUnEEgwsepKMKrHYjpg2zBXa94mWb PBFw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1772732992; x=1773337792; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=ZMBnwFdtbwEV59MpPwBswm8MRP35o4wwDus6WFw1l3k=; b=B/wmOuodJGK2ZU7Tcd4Rs+jRT6N2cqHw/Re24s2roXqjSO4oQ/9lOBuQTq6FDLeuNx V4QaAupzwwMqFy3F+LpVJdmsqNLq/kW9WWGeFsfxYTGDUUeNPCwDx+Q3hR5G88qPhzCZ 7C7VnJWUEW6Zmz4RPt+CEHidyTdc9uHVoGUp/xau2wTRxORPO9IW6+JqNYVoptXEq8nQ CAb/6Z5DXI85Zc+4XQxzaLRh2TQKKKHUJRELIW+YvYtt2OMmGaOGLyxAW5ABsQ4Az27q DRRqSeoqI3N5BWR3onokmS+4mGAiSQNNz6f0yXbr582C/VGEklv0RlRNsN6up3aTbDMG AY0g== X-Forwarded-Encrypted: i=1; AJvYcCUU3NKfStdn0SOoAWFOjYndDXAGLIIFifKMg8a+37kv2HkB0trf7ms2iIaP55+VtOZEfRIfe87nJKCVVXWQDSytuteW@freebsd.org X-Gm-Message-State: AOJu0YybXbayfN3bcdjiBKFrV/3IWUG+Z+U1Sxy9GJV4sMRYOQIqfSb1 km3J5GWUNW1cG6oxIHAf0oxZ5PwsEYdL3fNn+ueCZhgu3f6yRj2fcVvWGF2qaxzfO8M= X-Gm-Gg: ATEYQzz0+kWPLzdprnLS3PrAzx727S5lN+vfyYbiBlHo6+mE6BsOUF7JqWUZ+0QfRNf h/1yeeHWIUXnQXxI7N/6Jdl8hp8QIYSKGKIDJTAIyYJ+ZyRXamcHeAuI4h3Yi5hHoPPZkaM6Fqq bBlURON8RMYYrfprykF6Gto3h57Q67qdvUtdtZBKbwrRf8R92SNukCf8dK9QTbI7Z7IcdNXM+yA j1VlUefNWrxEprBRgBjMtZICuCDDGxuXFIo5mdzCVLbEIb07g0c+q8UXEuBv0IM4AQ2wqxFSPBi iP/54qIw4ZE3809eh0mKBPptIccE7jib/nnEJ3uiYJE4K74oP7bJDQBOdt3FbxvRfXK4CdNVTnj iSGAxXyju/Y4o6LJugt84uhtAzGh3eFlh9BRnlJ7XJYc4yo4jvoWnWbBBBJX2qM7Lq1Os/hy9GS 8NRKgR X-Received: by 2002:a05:6830:3902:b0:7cf:e4a1:8b56 with SMTP id 46e09a7af769-7d6da20ec7amr3779101a34.36.1772732991968; Thu, 05 Mar 2026 09:49:51 -0800 (PST) Received: from mutt-hbsd ([2001:470:4001:1::95]) by smtp.gmail.com with ESMTPSA id 46e09a7af769-7d5866269a8sm18563003a34.13.2026.03.05.09.49.51 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 05 Mar 2026 09:49:51 -0800 (PST) Date: Thu, 5 Mar 2026 17:49:51 +0000 From: Shawn Webb To: Baptiste Daroussin Cc: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org Subject: Re: git: 6d2a147ae558 - main - libedit: fix use after free Message-ID: X-Operating-System: FreeBSD mutt-hbsd 15.0-STABLE-HBSD FreeBSD 15.0-STABLE-HBSD HARDENEDBSD amd64 X-PGP-Key: https://git.hardenedbsd.org/hardenedbsd/pubkeys/-/blob/master/Shawn_Webb/03A4CBEBB82EA5A67D9F3853FF2E67A277F8E1FA.pub.asc References: <69a9aba5.38ca9.25c6649c@gitrepo.freebsd.org> List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-all@freebsd.org Sender: owner-dev-commits-src-all@FreeBSD.org MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="ubs7vg3hq72cyggd" Content-Disposition: inline In-Reply-To: <69a9aba5.38ca9.25c6649c@gitrepo.freebsd.org> X-Rspamd-Pre-Result: action=no action; module=replies; Message is reply to one we originated X-Spamd-Result: default: False [-4.00 / 15.00]; REPLY(-4.00)[]; ASN(0.00)[asn:15169, ipnet:2607:f8b0::/32, country:US] X-Rspamd-Queue-Id: 4fRcW56dHCz3vSq X-Spamd-Bar: ---- --ubs7vg3hq72cyggd Content-Type: text/plain; protected-headers=v1; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Subject: Re: git: 6d2a147ae558 - main - libedit: fix use after free MIME-Version: 1.0 On Thu, Mar 05, 2026 at 04:13:25PM +0000, Baptiste Daroussin wrote: > The branch main has been updated by bapt: >=20 > URL: https://cgit.FreeBSD.org/src/commit/?id=3D6d2a147ae558ef423e3df451a9= 049200b291a8d0 >=20 > commit 6d2a147ae558ef423e3df451a9049200b291a8d0 > Author: Baptiste Daroussin > AuthorDate: 2026-03-05 16:12:51 +0000 > Commit: Baptiste Daroussin > CommitDate: 2026-03-05 16:13:08 +0000 >=20 > libedit: fix use after free > --- > contrib/libedit/map.c | 4 ++-- > 1 file changed, 2 insertions(+), 2 deletions(-) Hey Baptiste, UAF bugs are typically thought to be security issues. Does this particular fix warrant a security advisory? The log is unfortunately lacking much useful metadata usually included in these kinds of commits. Thanks, --=20 Shawn Webb Cofounder / Security Engineer HardenedBSD Signal Username: shawn_webb.74 Tor-ified Signal: +1 303-901-1600 / shawn_webb_opsec.50 https://git.hardenedbsd.org/hardenedbsd/pubkeys/-/raw/master/Shawn_Webb/03A= 4CBEBB82EA5A67D9F3853FF2E67A277F8E1FA.pub.asc --ubs7vg3hq72cyggd Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEEA6TL67gupaZ9nzhT/y5nonf44foFAmmpwjEACgkQ/y5nonf4 4fpiuw//YUv9qJe9z5z7fSkbERGBGbPC61R/lSxBw9irXRdNjs2G+7fPKJkxiAak GDwMgfR+Ia62uv6vkBpxcU8NanTZ1GzhkZ1NFhlkw+BiD6D6ZRhPqEnaQNqIb2mi ii5pDUoNXrTEnMiGY+aQqZl9DHIJhsCpAzgcSin2fcByjDE9qRjM5823/fwpjDjw PGnBPWYjCaShiPocDoCa6Vvp7te71tHRmwoe8JFzIn6pgWooutdzhR80e7Ll/yFS FVoYdKnq6L92tNTchPwTOpCxNbocmGDH4jeRYxvNiOc6oI6NmrMN2tko38vaR79j F6c5lg4n07C0y48IVSPhEEpGs4cK+tJ6yNytM7AlzWzb/raWVSK7+E0GYjpcBuLx pIthcXloFHYBDVe/dSbouQV1f6NrVO5S/BT4pbQ+lMc3B4MEsktCtRbLDRWEz1Ul 3iVpJmHm5b5FxFkUay2L3JyCwAOHBAAZPfwIlc2POStJ2sGaoIpl76bGzUzWdbuN glE26BYcqUcMEOoWJnufkYt/T/ANX5ETFoxnQZrR3kihi6n03wECVs95lVFkdZiZ 7LV+yxpKnLEfcmUll6rtIU6K2tCpBq+rdQBS688aN8l0FTv47SsQQ4y7TtnH0xDW 4Jk3gM+AijYLBGHcEy9iDc8RcMV/JIF/kAOBVnDR0l62IG+ewmI= =A3t8 -----END PGP SIGNATURE----- --ubs7vg3hq72cyggd--