[Bug 1977694] Re: [CVE-2022-24713] Denial of service in compiler with rust-regex

2022-06-05 Thread Ubuntu Foundations Team Bug Bot
The attachment "Proposed Jammy Patch" seems to be a debdiff. The ubuntu-sponsors team has been subscribed to the bug report so that they can review and hopefully sponsor the debdiff. If the attachment isn't a patch, please remove the "patch" flag from the attachment, remove the "patch" tag, and i

[Bug 1977694] Re: [CVE-2022-24713] Denial of service in compiler with rust-regex

2022-06-05 Thread Joshua Peisach
** Description changed: There is a denial of service in rust-regex. Below is an SRU template to prepare for patching CVE-2022-24713. - https://ubuntu.com/security/CVE-2022-24713 - https://blog.rust-lang.org/2022/03/08/cve-2022-24713.html - https://github.com/rust-lang/regex/commit/ae70b41d

[Bug 1977694] Re: [CVE-2022-24713] Denial of service in compiler with rust-regex

2022-06-05 Thread Joshua Peisach
** Patch added: "Proposed Jammy Patch" https://bugs.launchpad.net/ubuntu/+source/rust-regex/+bug/1977694/+attachment/5594991/+files/rust-regex_1.5.4-1ubuntu0.1.debdiff ** Information type changed from Private Security to Public Security -- You received this bug notification because you are a