VDB
Sign up
—

GO-2023-1766

Denial of service from memory leak in github.com/ipfs/go-libipfs

Quick fix

GO-2023-1766 — github.com/ipfs/go-libipfs: upgrade to the fixed version with the command below.

go get github.com/ipfs/go-libipfs@v0.4.1

Details

An attacker can cause a Bitswap server to allocate and leak unbounded amounts of memory.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/ipfs/go-libipfs
Introduced in: 0Fixed in: 0.4.1
Fixgo get github.com/ipfs/go-libipfs@v0.4.1
Go/github.com/ipfs/go-bitswap
Introduced in: 0Fixed in: 0.12.0
Fixgo get github.com/ipfs/go-bitswap@v0.12.0

References