Files
mruby-mruby/SECURITY.md
T
Yukihiro "Matz" Matsumoto ce3b1c4780 SECURITY.md: added memory allocation error as a non security issue.
mruby expects `malloc(3)` returns `NULL` for too big allocations, so
even if big object allocation (e.g.  `[1,2,3]*268888888888888818`)
caused ASAN/Valgrind warnings, it's intentional, and we won't consider
the warning as a security issue.
2022-02-20 18:39:34 +09:00

546 B

Security Policy

Reporting a Vulnerability

If you have any security concern, contact matz@ruby.or.jp.

Scope

We consider following issues as vulnerabilities:

  • Remote code execution
  • Crash caused by a valid Ruby script

We don't consider following issues as vulnerabilities:

  • Runtime C undefined behavior (including integer overflow)
  • Crash caused by misused API
  • Crash caused by modified compiled binary
  • ASAN/Valgrind warning for too big memory allocation mruby assumes malloc(3) returns NULL for too big allocations