GHSA-87x9-7grx-m28v
notation-go has excessive memory allocation on verification
Quick fix
GHSA-87x9-7grx-m28v — github.com/notaryproject/notation-go: upgrade to the fixed version with the command below.
go get github.com/notaryproject/notation-go@v1.0.0-rc.3Details
### Impact
`notation-go` users will find their application using excessive memory when verifying signatures and the application will be finally killed, and thus availability is impacted.
### Patches
The problem has been patched in the release [v1.0.0-rc.3](https://github.com/notaryproject/notation-go/releases/tag/v1.0.0-rc.3). Users should upgrade their `notation-go` packages to `v1.0.0-rc.3` or above.
### Workarounds
Users can review their own trust policy file and check if the identity string contains `=#`. Meanwhile, users should only put trusted certificates in their trust stores referenced by their own trust policy files, and make sure the `authenticity` validation is set to `enforce`
### Credits
The `notation-go` project would like to thank Adam Korczynski (@AdamKorcz) for responsibly disclosing this issue during a security fuzzing audit sponsored by CNCF and Shiwei Zhang (@shizhMSFT) for root cause analysis and detailed vulnerability report.
### References
- [Resource exhaustion attacks](https://en.wikipedia.org/wiki/Resource_exhaustion_attack)
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 1.0.0-rc.3go get github.com/notaryproject/notation-go@v1.0.0-rc.3References
- https://github.com/notaryproject/notation-go/security/advisories/GHSA-87x9-7grx-m28v[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-25656[ADVISORY]
- https://github.com/notaryproject/notation-go/pull/275[WEB]
- https://github.com/notaryproject/notation-go[PACKAGE]
- https://github.com/notaryproject/notation-go/releases/tag/v1.0.0-rc.3[WEB]