{"id":"RUSTSEC-2026-0184","summary":"Potential undefined behavior with Signature from a buffer-created BlameHunk","details":"When a `Blame` is created via `Blame::blame_buffer()`, and a `BlameHunk` is retrieved, the pointers to the original author, original committer, final author, and final committer may be null if unavailable. The corresponding `BlameHunk` methods then create `Signature`s based on null pointers; attempting to access the data of the `Signature`s leads to dereferencing null pointers.","modified":"2026-06-17T14:00:05.672935662Z","published":"2026-05-13T12:00:00Z","database_specific":{"license":"CC0-1.0"},"references":[{"type":"PACKAGE","url":"https://crates.io/crates/git2"},{"type":"ADVISORY","url":"https://rustsec.org/advisories/RUSTSEC-2026-0184.html"},{"type":"WEB","url":"https://github.com/rust-lang/git2-rs/pull/1254"}],"affected":[{"package":{"name":"git2","ecosystem":"crates.io","purl":"pkg:cargo/git2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.0.0-0"},{"fixed":"0.21.0"}]}],"ecosystem_specific":{"affected_functions":null,"affects":{"arch":[],"os":[],"functions":[]}},"database_specific":{"source":"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0184.json","categories":[],"cvss":null,"informational":"unsound"}}],"schema_version":"1.7.5"}