GHSA-jhf3-xxhw-2wpp
go-git: Maliciously crafted idx file can cause asymmetric memory consumption
Quick fix
GHSA-jhf3-xxhw-2wpp — github.com/go-git/go-git/v5: upgrade to the fixed version with the command below.
go get github.com/go-git/go-git/v5@v5.17.1Details
### Impact
A vulnerability has been identified in which a maliciously crafted `.idx` file can cause asymmetric memory consumption, potentially exhausting available memory and resulting in a Denial of Service (DoS) condition.
Exploitation requires write access to the local repository's `.git` directory, it order to create or alter existing `.idx` files.
### Patches
Users should upgrade to `v5.17.1`, or the latest `v6` [pseudo-version](https://go.dev/ref/mod#pseudo-versions), in order to mitigate this vulnerability.
### Credit
The go-git maintainers thank @kq5y for finding and reporting this issue privately to the `go-git` project.
Are you affected?
Enter the version of the package you're using.
Affected packages
5.0.0Fixed in: 5.17.1go get github.com/go-git/go-git/v5@v5.17.1