Skip to content

Fix CVE-2022-36944 for LazyList#569

Merged
lrytz merged 1 commit intomainfrom
marissa/cve-2022-36944
Nov 25, 2022
Merged

Fix CVE-2022-36944 for LazyList#569
lrytz merged 1 commit intomainfrom
marissa/cve-2022-36944

Conversation

@NthPortal
Copy link
Copy Markdown
Contributor

Backport fix for CVE-2022-36944 from 2.13.

Code copy-pasted in a browser.

Fixes #557

Loading
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport Backport of changes from 2.13 to methods/classes already present bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

For security, prevent Function0 execution during LazyList deserialization (backport from 2.13)

3 participants