Skip to content

Mark CVE-2023-37365 (hnswlib double free) as fixed in 0.8.0#7231

Closed
ilyajob05 wants to merge 3 commits into
github:ilyajob05/advisory-improvement-7231from
ilyajob05:patch-2
Closed

Mark CVE-2023-37365 (hnswlib double free) as fixed in 0.8.0#7231
ilyajob05 wants to merge 3 commits into
github:ilyajob05/advisory-improvement-7231from
ilyajob05:patch-2

Conversation

@ilyajob05
Copy link
Copy Markdown

The double-free vulnerability (CVE-2023-37365) was fixed by capping the M parameter to 10000. The fix was merged via nmslib/hnswlib#508 (original fix by @emollier in #484, integrated and improved by @jlmelville in #508).
The fix is included in release v0.8.0.
This change updates the advisory to specify the fixed version so downstream scanners (Snyk, Dependabot, Trivy) correctly identify patched installations.

The double-free vulnerability (CVE-2023-37365) was fixed by capping the M parameter to 10000. The fix was merged via nmslib/hnswlib#508 (original fix by @emollier in github#484, integrated and improved by @jlmelville in github#508).
  The fix is included in release v0.8.0.
  This change updates the advisory to specify the fixed version so downstream scanners (Snyk, Dependabot, Trivy) correctly identify patched installations.
@ilyajob05 ilyajob05 closed this Mar 24, 2026
@ilyajob05 ilyajob05 deleted the patch-2 branch March 24, 2026 22:54
@ilyajob05 ilyajob05 restored the patch-2 branch March 25, 2026 18:32
Updated the advisory to reflect the fix for the hnswlib double free vulnerability in version 0.8.0, including details about the changes made and the release date.
@ilyajob05 ilyajob05 reopened this Mar 25, 2026
@github-actions github-actions Bot changed the base branch from main to ilyajob05/advisory-improvement-7231 March 25, 2026 18:44
@ilyajob05 ilyajob05 closed this Mar 25, 2026
@ilyajob05 ilyajob05 deleted the patch-2 branch March 25, 2026 18:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant