GHSA-2h6c-j3gf-xp9r
IPFS go-bitfield vulnerable to DoS via malformed size arguments
Quick fix
GHSA-2h6c-j3gf-xp9r — github.com/ipfs/go-bitfield: upgrade to the fixed version with the command below.
go get github.com/ipfs/go-bitfield@v1.1.0Details
### Impact When feeding untrusted user input into the size parameter of `NewBitfield` and `FromBytes` functions, an attacker can trigger `panic`s.
This happen when the `size` is a not a multiple of `8` or is negative. There were already a note in the `NewBitfield` documentation: > ``` > Panics if size is not a multiple of 8. > ````
But it incomplete and missing from `FromBytes`'s documentation.
This has been replaced by returning an `(Bitfield, error)` and returning a non nil error if the size is wrong.
### Patches - https://github.com/ipfs/go-bitfield/commit/5e1d256fe043fc4163343ccca83862c69c52e579
### Workarounds - Ensure `size%8 == 0 && size >= 0` yourself before calling `NewBitfield` or `FromBytes`
### References - https://github.com/ipfs/go-unixfs/security/advisories/GHSA-q264-w97q-q778
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 1.1.0go get github.com/ipfs/go-bitfield@v1.1.0References
- https://github.com/ipfs/go-bitfield/security/advisories/GHSA-2h6c-j3gf-xp9r[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-23626[ADVISORY]
- https://github.com/ipfs/go-bitfield/commit/5e1d256fe043fc4163343ccca83862c69c52e579[WEB]
- https://github.com/ipfs/go-bitfield[PACKAGE]
- https://pkg.go.dev/vuln/GO-2023-1558[WEB]