Zsh Mailing List Archive
Messages sorted by: Reverse Date, Date, Thread, Author

Re: Follow-up to here-document bug reported on zsh-security



Apologies that this sat for so long.

On Wed, Nov 26, 2025 at 4:12 PM Oliver Kiddle <opk@xxxxxxx> wrote:
>
> Bart: did you perhaps miss the second issue that was reported in
> the same mail - the use after free in scanendscope() that probably
> arrived in 53568 / abd541e18c.

I think you mean this?

I wrote (on zsh-security):
> > ** Fix for following AddressSanitizer error **
>
> Thanks for this but the parameter handling in scanendscope() is
> undergoing some significant rewrites that remove most of the code
> around your changes.  It will be helpful if you can check again after
> the next test release.

I don't think there's been a next test release yet, but Nathan if you
can check out the latest from git and test that, it would be helpful.




Messages sorted by: Reverse Date, Date, Thread, Author