media-converter: Update bumpalo to avoid use-after-free.
In affected project of this crate, the lifetime of the iterator produced by Vec::into_iter() is not constrained to the lifetime of the Bump that allocated the vector's memory. Using the iterator after the Bump is dropped causes use-after-free accesses. Link: https://github.com/ValveSoftware/Proton/pull/6792
This commit is contained in:
parent
46304cde3d
commit
a76c324c30
1 changed files with 2 additions and 2 deletions
4
media-converter/Cargo.lock
generated
4
media-converter/Cargo.lock
generated
|
@ -43,9 +43,9 @@ checksum = "bef38d45163c2f1dde094a7dfd33ccf595c92905c8f8f4fdc18d06fb1037718a"
|
|||
|
||||
[[package]]
|
||||
name = "bumpalo"
|
||||
version = "3.11.0"
|
||||
version = "3.12.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "c1ad822118d20d2c234f427000d5acc36eabe1e29a348c89b63dd60b13f28e5d"
|
||||
checksum = "3c6ed94e98ecff0c12dd1b04c15ec0d7d9458ca8fe806cea6f12954efe74c63b"
|
||||
|
||||
[[package]]
|
||||
name = "cfg-expr"
|
||||
|
|
Loading…
Reference in a new issue