← Back to issue list

Fix ReDoS (GHSL-2024-323)

View original Github issue

Metadata

Project
snapcraft
Number
#5210
Type
pull request
State
closed
Author
kevinbackhouse
Labels
Created
Updated
Closed

Current evaluation

Superseded by PR #5213, which resolves the ReDoS vulnerability (GHSL-2024-323) and corrects the underlying regex logic. The original author acknowledged the improved fix and closed this pull request.

Suggested action:

No scores available.

Issue body

- [x] Have you followed the [guidelines for contributing](https://github.com/canonical/snapcraft/blob/main/CONTRIBUTING.md)? - [x] Have you signed the [CLA](http://www.ubuntu.com/legal/contributors/)? - [ ] Have you successfully run `tox run -m lint`? - [ ] Have you successfully run `tox run -e test-py310`? (supported versions: `py39`, `py310`, `py311`, `py312`) ----- Fixes a ReDoS: https://bugs.launchpad.net/snapcraft/+bug/2086622 (GHSL-2024-323)

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Superseded by PR #5213, which resolves the ReDoS vulnerability (GHSL-2024-323) and corrects the underlying regex logic. The original author acknowledged the improved fix and closed this pull request.
qwen3.6-35b-a3b-mtp-q6 Superseded by PR #5213. The original pull request addressed a ReDoS vulnerability (GHSL-2024-323), but a maintainer submitted a superior fix that also corrects the underlying regex. The original PR was closed in favor of the maintainer's solution.
qwen3.6-35b-a3b-mtp-q6 Superseded by PR #5213, which provides a more precise regex fix for the ReDoS vulnerability (GHSL-2024-323). The original PR was closed without merging after a maintainer identified a superior approach that also corrects incorrect duration parsing.

Update history

No update history recorded yet.

Related issues

No related issues found above the similarity threshold.