The kstring integration in gix-attributes is unsound
Low severity
GitHub Reviewed
Published
Jul 25, 2024
to the GitHub Advisory Database
•
Updated Jan 21, 2025
Description
Published to the GitHub Advisory Database
Jul 25, 2024
Reviewed
Jul 25, 2024
Last updated
Jan 21, 2025
gix-attributes(instate::ValueRef) unsafely creates a&strfrom a&[u8]containing non-UTF8 data, with the justification that so long as nothing reads the&strand relies on it being UTF-8 in the&str, there is no UB:// SAFETY: our API makes accessing that value as `str` impossible, so illformed UTF8 is never exposed as such.The problem is that the non-UTF8
stris exposed to outside code: first to thekstringcrate itself, which requires UTF-8 in its documentation and may have UB as a consequence of this, but also toserde, where it propagates to e.g.serde_json,serde_yaml, etc., where the same problems occur.This is not sound, and it could cause further UB down the line in these places that can view the
&str.References