VDB
Sign up
MEDIUM5.0

GHSA-jhf3-xxhw-2wpp

go-git: Maliciously crafted idx file can cause asymmetric memory consumption

Quick fix

GHSA-jhf3-xxhw-2wpp — github.com/go-git/go-git/v5: upgrade to the fixed version with the command below.

go get github.com/go-git/go-git/v5@v5.17.1

Details

### Impact

A vulnerability has been identified in which a maliciously crafted `.idx` file can cause asymmetric memory consumption, potentially exhausting available memory and resulting in a Denial of Service (DoS) condition.

Exploitation requires write access to the local repository's `.git` directory, it order to create or alter existing `.idx` files.

### Patches

Users should upgrade to `v5.17.1`, or the latest `v6` [pseudo-version](https://go.dev/ref/mod#pseudo-versions), in order to mitigate this vulnerability.

### Credit

The go-git maintainers thank @kq5y for finding and reporting this issue privately to the `go-git` project.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/go-git/go-git/v5
Introduced in: 5.0.0Fixed in: 5.17.1
Fixgo get github.com/go-git/go-git/v5@v5.17.1

References