Skip to content

PerfView and TraceEvent 3.2.4

Choose a tag to compare

@brianrob brianrob released this 16 Jun 16:35
· 26 commits to main since this release
60c3232

Security

This release contains security hardening fixes for a number of malformed-input parsing and path-traversal vulnerabilities:

  • Bounds-checking for malformed event payloads in the BPerf ULZ777 decompressor and event-record parser
  • Bounds-checking for malformed metadata in the GCDynamic, RegisteredTraceEventParser (TDH), Dynamic, and EventPipe V3 parsers
  • Bounds-checking for malformed PE CodeView and Resource directory entries
  • Path containment hardening for PDB extraction (zipped ETL + container PDBs), DiagSession resource extraction, R2R perf map writes, PdbScope module paths, and dynamic manifest writes
  • Path-traversal and command-execution hardening for Source Server lookups

What's Changed

Full Changelog: v3.2.3...v3.2.4