VDB
Sign up
MEDIUM5.3

GHSA-67fx-wx78-jx33

Helm vulnerable to denial of service through schema file

Quick fix

GHSA-67fx-wx78-jx33 — helm.sh/helm/v3: upgrade to the fixed version with the command below.

go get helm.sh/helm/v3@v3.10.3

Details

Fuzz testing, by Ada Logics and sponsored by the CNCF, identified input to functions in the `_chartutil_` package that can cause a segmentation violation. Applications that use functions from the `_chartutil_` package in the Helm SDK can have a Denial of Service attack when they use this package and it panics.

### Impact

The `_chartutil_` package contains a parser that loads a JSON Schema validation file. For example, the Helm client when rendering a chart will validate its values with the schema file. The `_chartutil_` package parses the schema file and loads it into structures Go can work with. Some schema files can cause array data structures to be created causing a memory violation.

Applications that use the `_chartutil_` package in the Helm SDK to parse a schema file can suffer a Denial of Service when that input causes a panic that cannot be recovered from.

The Helm Client will panic with a schema file that causes a memory violation panic. Helm is not a long running service so the panic will not affect future uses of the Helm client.

### Patches

This issue has been resolved in 3.10.3.

### Workarounds

SDK users can validate schema files that are correctly formatted before passing them to the `_chartutil_` functions.

### For more information

Helm's security policy is spelled out in detail in our [SECURITY](https://github.com/helm/community/blob/master/SECURITY.md) document.

### Credits

Disclosed by Ada Logics in a fuzzing audit sponsored by CNCF.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/helm.sh/helm/v3
Introduced in: 0Fixed in: 3.10.3
Fixgo get helm.sh/helm/v3@v3.10.3

References