VDB
Sign up
MEDIUM5.5

GHSA-6p9p-q6wh-9j89

apko affected by unbounded resource consumption in expandapk.Split on attacker-controlled .apk streams

Quick fix

GHSA-6p9p-q6wh-9j89 — chainguard.dev/apko: upgrade to the fixed version with the command below.

go get chainguard.dev/apko@v1.1.0

Details

`expandapk.Split` drains the first gzip stream of an APK archive via `io.Copy(io.Discard, gzi)` without explicit bounds. With an attacker-controlled input stream, this can force large gzip inflation work and lead to resource exhaustion (availability impact). The `Split` function reads the first tar header, then drains the remainder of the gzip stream by reading from the gzip reader directly without any maximum uncompressed byte limit or inflate-ratio cap. A caller that parses attacker-controlled APK streams may be forced to spend excessive CPU time inflating gzip data, leading to timeouts or process slowdown. **Fix:** Fixed with [2be3903](https://github.com/chainguard-dev/apko/commit/2be3903fe194ad46351840f0569b35f5ac965f09), Released in v1.1.0. **Acknowledgements** apko thanks Oleh Konko from [1seal](https://1seal.org/) for discovering and reporting this issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/chainguard.dev/apko
Introduced in: 0.14.8Fixed in: 1.1.0
Fixgo get chainguard.dev/apko@v1.1.0

References