Hello,
I have identified a reproducible memory-safety issue in DeskX.
The issue is reachable through the RGB/frame decoding path on a clean checkout with AddressSanitizer enabled. I have prepared a small report package containing:
affected commit information
standalone reproducer
minimized malformed input
ASan/UBSan run logs
source-level root cause notes
clean-checkout reproduction steps
suggested fix direction
I would prefer not to disclose the malformed input, reproducer details, source locations, or sanitizer output publicly before the maintainer has had a chance to review them.
Is there a preferred private security contact, email address, or disclosure route for this project?
Best regards,
Yukimura
Hello,
I have identified a reproducible memory-safety issue in DeskX.
The issue is reachable through the RGB/frame decoding path on a clean checkout with AddressSanitizer enabled. I have prepared a small report package containing:
affected commit information
standalone reproducer
minimized malformed input
ASan/UBSan run logs
source-level root cause notes
clean-checkout reproduction steps
suggested fix direction
I would prefer not to disclose the malformed input, reproducer details, source locations, or sanitizer output publicly before the maintainer has had a chance to review them.
Is there a preferred private security contact, email address, or disclosure route for this project?
Best regards,
Yukimura