diff options
author | Edward Thomson <ethomson@edwardthomson.com> | 2022-04-12 15:42:08 -0400 |
---|---|---|
committer | Edward Thomson <ethomson@edwardthomson.com> | 2022-04-12 15:42:08 -0400 |
commit | 0e5eff4d7bb29dc3b2b305ffc8e40430ca2d7aff (patch) | |
tree | a4e8fe6d36ef65212f548235801e779c5cfbf876 /docs | |
parent | a63532aafd120692266459e55a1a3af03507a2d5 (diff) | |
download | libgit2-0e5eff4d7bb29dc3b2b305ffc8e40430ca2d7aff.tar.gz |
meta: changelog for v1.4.3
Diffstat (limited to 'docs')
-rw-r--r-- | docs/changelog.md | 20 |
1 files changed, 20 insertions, 0 deletions
diff --git a/docs/changelog.md b/docs/changelog.md index 5a5ef8c36..32a67d2c7 100644 --- a/docs/changelog.md +++ b/docs/changelog.md @@ -1,3 +1,23 @@ +v1.4.3 +------ + +🔒 This is a security release to provide compatibility with git's changes to address [CVE 2022-24765](https://github.blog/2022-04-12-git-security-vulnerability-announced/). + +**libgit2 is not directly affected** by this vulnerability, because libgit2 does not directly invoke any executable. But we are providing these changes as a security release for any users that use libgit2 for repository discovery and then _also_ use git on that repository. In this release, we will now validate that the user opening the repository is the same user that owns the on-disk repository. This is to match git's behavior. + +In addition, we are providing several correctness fixes where invalid input can lead to a crash. These may prevent possible denial of service attacks. At this time there are not known exploits to these issues. + +Full list of changes: + +* Validate repository directory ownership (v1.4) by @ethomson in https://github.com/libgit2/libgit2/pull/6267 +* midx: Fix an undefined behavior (left-shift signed overflow) by @lhchavez in https://github.com/libgit2/libgit2/pull/6260 +* fetch: support OID refspec without dst by @ethomson in https://github.com/libgit2/libgit2/pull/6251 +* Fix crash when regenerating a patch with unquoted spaces in filename by @jorio in https://github.com/libgit2/libgit2/pull/6244 + +All users of the v1.4 release line are recommended to upgrade. + +**Full Changelog**: https://github.com/libgit2/libgit2/compare/v1.4.2...v1.4.3 + v1.4.2 ------ |