mirror of
https://github.com/mruby/mruby
synced 2026-06-08 16:11:16 +00:00
ce3b1c4780
mruby expects `malloc(3)` returns `NULL` for too big allocations, so even if big object allocation (e.g. `[1,2,3]*268888888888888818`) caused ASAN/Valgrind warnings, it's intentional, and we won't consider the warning as a security issue.
546 B
546 B
Security Policy
Reporting a Vulnerability
If you have any security concern, contact matz@ruby.or.jp.
Scope
We consider following issues as vulnerabilities:
- Remote code execution
- Crash caused by a valid Ruby script
We don't consider following issues as vulnerabilities:
- Runtime C undefined behavior (including integer overflow)
- Crash caused by misused API
- Crash caused by modified compiled binary
- ASAN/Valgrind warning for too big memory allocation
mruby assumes
malloc(3)returnsNULLfor too big allocations