CVE-2021-46168: Spin v6.5.1 was discovered to contain an out-of-bounds write in lex() at spinlex.c.
The bug has been closed via the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=69c2ae786d9151a8358198a73a8bcd0583ac9a1f commit 69c2ae786d9151a8358198a73a8bcd0583ac9a1f Author: Marek Szuba <marecki@gentoo.org> AuthorDate: 2022-01-16 08:56:16 +0000 Commit: Marek Szuba <marecki@gentoo.org> CommitDate: 2022-01-16 08:57:12 +0000 sci-mathematics/spin: backport upstream fix for CVE-2021-46168 Closes: https://bugs.gentoo.org/831220 Signed-off-by: Marek Szuba <marecki@gentoo.org> .../spin/files/spin-6.5.2-nesting_limit.patch | 55 ++++++++++++++++++++++ .../{spin-6.5.2.ebuild => spin-6.5.2-r1.ebuild} | 3 +- 2 files changed, 57 insertions(+), 1 deletion(-)
No vulnerable versions left in the tree.
All done, thanks!
(In reply to Marek Szuba from comment #2) > No vulnerable versions left in the tree. (but please don't close security bugs yourself to ensure procedure is followed (metadata updated, no other action required from us, etc))