Skip to content

Add advisory for infisearch_common - #3106

Open
MJUCOM wants to merge 1 commit into
rustsec:mainfrom
MJUCOM:advisory-infisearch-common
Open

Add advisory for infisearch_common#3106
MJUCOM wants to merge 1 commit into
rustsec:mainfrom
MJUCOM:advisory-infisearch-common

Conversation

@MJUCOM

@MJUCOM MJUCOM commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Affected crate(s)

  • infisearch_common (259 recent downloads per crates.io)

Links to upstream issue(s) or PR(s)

Severity

This is submitted as an informational unsound advisory. The reported issue involves unchecked indexing in a safe method, which can lead to out-of-bounds access and undefined behavior.

Checklist

  • Advisory filename(s) starts with RUSTSEC-0000-0000 as the ID
  • date field is set to the public disclosure date
  • Contains a concise and descriptive title after advisory metadata
  • Asked maintainer(s) if publishing an advisory is appropriate

@djc

djc commented Aug 4, 2026

Copy link
Copy Markdown
Member

Please add the number of recent downloads on crates.io, as in the PR template, for all of your PRs.

@MJUCOM

MJUCOM commented Aug 4, 2026

Copy link
Copy Markdown
Contributor Author

Thank you for checking and pointing this out. I have updated my recent PRs to include the recent downloads count according to the PR template.

@djc

djc commented Aug 4, 2026

Copy link
Copy Markdown
Member
  • Asked maintainer(s) if publishing an advisory is appropriate

Also this bullet is there for a reason. Please discuss with the upstream maintainer(s) for each PR.

@MJUCOM

MJUCOM commented Aug 4, 2026

Copy link
Copy Markdown
Contributor Author

Thank you for your guidance.

We reported the issue upstream, but we have not received an explicit maintainer response confirming the issues, so I left the maintainer-confirmation checklist item unchecked.

May I kindly ask whether this situation makes the advisory difficult to accept for RustSec, or whether there is any additional information I should provide to help with the review?

@djc

djc commented Aug 13, 2026

Copy link
Copy Markdown
Member

We typically require approval from maintainers (that are active/reachable) before publishing a RustSec advisory.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants