GHSA-cx7h-h87r-jpgr
The kstring integration in gix-attributes is unsound
Details
`gix-attributes` (in [`state::ValueRef`](https://github.com/Byron/gitoxide/blob/gix-attributes-v0.22.2/gix-attributes/src/state.rs#L19-L27)) unsafely creates a `&str` from a `&[u8]` containing non-UTF8 data, with the justification that so long as nothing reads the `&str` and relies on it being UTF-8 in the `&str`, there is no UB:
```rust // SAFETY: our API makes accessing that value as `str` impossible, so illformed UTF8 is never exposed as such. ```
The problem is that the non-UTF8 `str` **is** exposed to outside code: first to the `kstring` crate itself, which requires UTF-8 in its documentation and may have UB as a consequence of this, but also to `serde`, where it propagates to e.g. `serde_json`, `serde_yaml`, etc., where the same problems occur.
This is not sound, and it could cause further UB down the line in these places that can view the `&str`.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 0.22.3Upgrade gix-attributes to 0.22.3 or newer (ecosystem crates.io).