Skip to content

Security vulnerabilities — how should I report them? #167

@0xkylm

Description

@0xkylm

Hi,

I found several security vulnerabilities in the ELF hash section parsing
(division by zero, heap out-of-bounds reads, integer overflow) that can be
triggered by a crafted ELF file. All confirmed with AddressSanitizer.

I couldn't find a SECURITY.md or private disclosure channel in the repo.
What is the preferred way to report security issues? I can share full
details, PoCs, and a patch PR through whatever channel you prefer.

Thanks

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions