Skip to content

Update rand advisory to include an additional patched version.#2795

Merged
djc merged 1 commit intorustsec:mainfrom
nwalfield:rand/update-rand
Apr 17, 2026
Merged

Update rand advisory to include an additional patched version.#2795
djc merged 1 commit intorustsec:mainfrom
nwalfield:rand/update-rand

Conversation

@nwalfield
Copy link
Copy Markdown
Contributor

The fix was backported to the 0.8 branch and released as version 0.8.6. Update the advisory to indicate that this version is also safe.

For details, please see rust-random/rand#1772 and rust-random/rand#1770 .

The fix was backported to the 0.8 branch and released as version
0.8.6.  Update the advisory to indicate that this version is also
safe.
@djc djc merged commit 6617d54 into rustsec:main Apr 17, 2026
1 check passed
@nwalfield
Copy link
Copy Markdown
Contributor Author

Thanks @djc for the quick reaction.

@djc
Copy link
Copy Markdown
Member

djc commented Apr 17, 2026

Thanks!

(Separately I'm curious to hear more about why you need OpenSSL support for Hickory in Sequoia -- a quick search found https://gitlab.com/sequoia-pgp/sequoia/-/work_items/1133 but that seems to be talking about the other direction...)

@nwalfield
Copy link
Copy Markdown
Contributor Author

The short answer is that some of our downstreams prefer OpenSSL to AWS-LC or ring. @decathorpe documented the Fedora and RHEL position here quite well, I think: hickory-dns/hickory-dns#3452 . (I'm happy to continue the discussion, but perhaps this is not the right place.)

@djc
Copy link
Copy Markdown
Member

djc commented Apr 17, 2026

(I'm djc on GitLab as well if you want to tag me in an issue over there.)

@xtqqczze
Copy link
Copy Markdown
Contributor

xtqqczze commented Apr 17, 2026

Affected versions of rand are >= 0.7, < 0.9.3 and 0.10.0.

This part needs updating too: #2796

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants