VDB
Sign up
HIGH7.5

GHSA-4gj3-6r43-3wfc

IPFS go-unixfsnode subject to DOS via HAMT Decoding Panics

Quick fix

GHSA-4gj3-6r43-3wfc — github.com/ipfs/go-unixfsnode: upgrade to the fixed version with the command below.

go get github.com/ipfs/go-unixfsnode@v1.5.2

Details

## Impact

Trying to read malformed HAMT sharded directories can cause panics and virtual memory leaks. If you are reading untrusted user input, an attacker can then trigger a panic.

This is caused by a bogus fanout parameter in the HAMT directory nodes. This includes checks returned in [ipfs/go-bitfield GHSA-2h6c-j3gf-xp9r](https://github.com/ipfs/go-bitfield/security/advisories/GHSA-2h6c-j3gf-xp9r), as well as limiting the fanout to <= 1024 (to avoid attempts of arbitrary sized allocations).

## Patches - https://github.com/ipfs/go-unixfsnode/commit/91b3d39d33ef0cd2aff2c95d50b2329350944b68 - https://github.com/ipfs/go-unixfsnode/commit/a4ed723727e0bdc2277158337c2fc0d82802d122

## References

* https://github.com/ipfs/go-unixfs/security/advisories/GHSA-q264-w97q-q778 * https://github.com/ipfs/go-bitfield/security/advisories/GHSA-2h6c-j3gf-xp9r

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/ipfs/go-unixfsnode
Introduced in: 0Fixed in: 1.5.2
Fixgo get github.com/ipfs/go-unixfsnode@v1.5.2

References