From 45e12cc668dba6e90df12ae1fa528af1e151d020 Mon Sep 17 00:00:00 2001 From: Mark Qvist Date: Wed, 22 Apr 2026 13:51:09 +0200 Subject: [PATCH] Prepare release --- Changelog.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Changelog.md b/Changelog.md index 343526d..d9cff84 100644 --- a/Changelog.md +++ b/Changelog.md @@ -2,7 +2,7 @@ This maintenance release fixes a critical security issue, that would allow an attacker to craft a BZ2 decompression bomb via Resource transfers or Buffer StreamDataMessage, causing an out-of-memory condition and crashing the receiving process via OOM killer. -Big thanks to @defidude for discovering and reporting this vulnerability! +Big thanks to @defidude (github.com/ratspeak) for discovering and reporting this vulnerability! **Changes** - Fixed bz2 decompression bomb vulnerability in Resource transfer assembly and Buffer StreamDataMessage unpacking.