sequoia-pgp hunt, iteration 3 (RUSTSEC-2024-0345 variant audit)
Iteration 3: results and what would not be a finding.
Read the writeup →Vulnerability research, detection engineering, and applied cryptography.
Iteration 3: results and what would not be a finding.
Read the writeup →Iteration 2: parser audit and candidate ranking.
Read the writeup →Recon and variant-seed inventory against sequoia-openpgp based on its historical RUSTSEC advisories.
Root-cause walk-through of CVE-2025-47934 (signature-verification bypass via msg.packets mutation) and a variant search against the v6.2.0 compression refactor.
Top-to-bottom audit log of systemd-coredumpd and systemd-resolved DNS parser. No findings; the writeup is the methodology and the dead ends.
Read the writeup →