—
GO-2023-1766
Denial of service from memory leak in github.com/ipfs/go-libipfs
Quick fix
GO-2023-1766 — github.com/ipfs/go-libipfs: upgrade to the fixed version with the command below.
go get github.com/ipfs/go-libipfs@v0.4.1Details
An attacker can cause a Bitswap server to allocate and leak unbounded amounts of memory.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/ipfs/go-libipfs
Introduced in:
0Fixed in: 0.4.1Fix
go get github.com/ipfs/go-libipfs@v0.4.1Go/github.com/ipfs/go-bitswap
Introduced in:
0Fixed in: 0.12.0Fix
go get github.com/ipfs/go-bitswap@v0.12.0