Bug#1041468: bookworm-pu: package hnswlib/0.6.2-2+deb12u1

2023-07-22 Thread Étienne Mollier
Hi Jonathan, Jonathan Wiltshire, on 2023-07-22: > Control: tag -1 confirmed > > On Wed, Jul 19, 2023 at 12:04:04PM +0200, Étienne Mollier wrote: > > hnswlib is affected by CVE-2023-37365 marked no-dsa, documented > > through the important bug #1041426. Quoting the CVE for short: > > hnswlib has

Bug#1041468: bookworm-pu: package hnswlib/0.6.2-2+deb12u1

2023-07-22 Thread Jonathan Wiltshire
Control: tag -1 confirmed On Wed, Jul 19, 2023 at 12:04:04PM +0200, Étienne Mollier wrote: > hnswlib is affected by CVE-2023-37365 marked no-dsa, documented > through the important bug #1041426. Quoting the CVE for short: > hnswlib has a double free in init_index when the M argument is a > large

Bug#1041468: bookworm-pu: package hnswlib/0.6.2-2+deb12u1

2023-07-19 Thread Étienne Mollier
Package: release.debian.org Severity: normal Tags: bookworm User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: hnsw...@packages.debian.org Control: affects -1 + src:hnswlib Hi Stable Release Managers, [ Reason ] hnswlib is affected by CVE-2023-37365 marked no-dsa, documented