Potential segfault in `localtime_r` invocations
Moderate severity
GitHub Reviewed
Published
Jun 16, 2022
to the GitHub Advisory Database
•
Updated Jan 12, 2023
Withdrawn
This advisory was withdrawn on Jul 21, 2022
Description
Published to the GitHub Advisory Database
Jun 16, 2022
Reviewed
Jun 16, 2022
Withdrawn
Jul 21, 2022
Last updated
Jan 12, 2023
Impact
Unix-like operating systems may segfault due to dereferencing a dangling pointer in specific circumstances. This requires an environment variable to be set in a different thread than the affected functions. This may occur without the user's knowledge, notably in a third-party library.
Workarounds
No workarounds are known.
References