GHSA-9h84-qmv7-982p
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion
Quick fix
GHSA-9h84-qmv7-982p — helm.sh/helm/v3: upgrade to the fixed version with the command below.
go get helm.sh/helm/v3@v3.18.5Details
A Helm contributor discovered that it was possible to craft a JSON Schema file in a manner which could cause Helm to use all available memory and have an out of memory (OOM) termination.
### Impact A malicious chart can point `$ref` in _values.schema.json_ to a device (e.g. `/dev/*`) or other problem file which could cause Helm to use all available memory and have an out of memory (OOM) termination.
### Patches This issue has been resolved in Helm v3.18.5.
### Workarounds Make sure that all Helm charts that are being loaded into Helm doesn't have any reference of `$ref` pointing to `/dev/zero`.
### References Helm's security policy is spelled out in detail in our [SECURITY](https://github.com/helm/community/blob/master/SECURITY.md) document.
### Credits Disclosed by Jakub Ciolek at AlphaSense.
Are you affected?
Enter the version of the package you're using.