VDB
Sign up
MEDIUM6.5

GHSA-9h84-qmv7-982p

Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion

Quick fix

GHSA-9h84-qmv7-982p — helm.sh/helm/v3: upgrade to the fixed version with the command below.

go get helm.sh/helm/v3@v3.18.5

Details

A Helm contributor discovered that it was possible to craft a JSON Schema file in a manner which could cause Helm to use all available memory and have an out of memory (OOM) termination.

### Impact A malicious chart can point `$ref` in _values.schema.json_ to a device (e.g. `/dev/*`) or other problem file which could cause Helm to use all available memory and have an out of memory (OOM) termination.

### Patches This issue has been resolved in Helm v3.18.5.

### Workarounds Make sure that all Helm charts that are being loaded into Helm doesn't have any reference of `$ref` pointing to `/dev/zero`.

### References Helm's security policy is spelled out in detail in our [SECURITY](https://github.com/helm/community/blob/master/SECURITY.md) document.

### Credits Disclosed by Jakub Ciolek at AlphaSense.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/helm.sh/helm/v3
Introduced in: 0Fixed in: 3.18.5
Fixgo get helm.sh/helm/v3@v3.18.5

References