VDB
Sign up
MEDIUM5.9

GHSA-846p-jg2w-w324

go-tuf affected by client DoS via malformed server response

Quick fix

GHSA-846p-jg2w-w324 — github.com/theupdateframework/go-tuf/v2: upgrade to the fixed version with the command below.

go get github.com/theupdateframework/go-tuf/v2@v2.3.1

Details

# Security Disclosure: Client DoS via malformed server response

## Summary

If the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic _during parsing_, causing a DoS. The panic happens before any signature is validated. This means that a compromised repository/mirror/cache can DoS clients without having access to any signing key.

## Impact

Client crashes upon receiving and parsing malformed TUF metadata. This can cause long running services to enter an restart/crash loop.

## Workarounds

None currently.

## Affected code

The `metadata.checkType` function did not properly type assert the (untrusted) input causing it to panic on malformed data.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/theupdateframework/go-tuf/v2
Introduced in: 0Fixed in: 2.3.1
Fixgo get github.com/theupdateframework/go-tuf/v2@v2.3.1

References