GHSA-q264-w97q-q778
Denial of service via HAMT Decoding Panics
Quick fix
GHSA-q264-w97q-q778 — github.com/ipfs/go-unixfs: upgrade to the fixed version with the command below.
go get github.com/ipfs/go-unixfs@v0.4.3Details
### Impact Trying to read malformed HAMT sharded directories can cause panics and virtual memory leaks. If you are reading untrusted user input, an attacker can then trigger a panic.
This is caused by bogus `fanout` parameter in the HAMT directory nodes. This include checks returned in [ipfs/go-bitfield GHSA-2h6c-j3gf-xp9r](https://github.com/ipfs/go-bitfield/security/advisories/GHSA-2h6c-j3gf-xp9r), as well as limiting the `fanout` to `<= 1024` (to avoid attempts of arbitrary sized allocations).
### Patches - https://github.com/ipfs/go-unixfs/commit/dbcc43ec3e2db0d01e8d80c55040bba3cf22cb4b
### Workarounds Do not feed untrusted user data to the decoding functions.
### References - https://github.com/ipfs/go-bitfield/security/advisories/GHSA-2h6c-j3gf-xp9r
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 0.4.3go get github.com/ipfs/go-unixfs@v0.4.3References
- https://github.com/ipfs/go-unixfs/security/advisories/GHSA-q264-w97q-q778[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-23625[ADVISORY]
- https://github.com/ipfs/go-unixfs/commit/467d139a640ecee4f2e74643dafcc58bb3b54175[WEB]
- https://github.com/advisories/GHSA-q264-w97q-q778[ADVISORY]
- https://github.com/ipfs/go-unixfs[PACKAGE]
- https://pkg.go.dev/vuln/GO-2023-1557[WEB]