CVE-2022-2879
Dashboard / Vulnerabilities / CVE-2022-2879
CVE-2022-2879
Summary: Unbounded memory consumption when reading headers in archive/tar
Details: Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocate unbounded amounts of memory, potentially causing resource exhaustion or panics. After fix, Reader.Read limits the maximum size of header blocks to 1 MiB.
References: https://go.dev/cl/439355, https://go.dev/issue/54853, https://groups.google.com/g/golang-announce/c/xtuG5faxtaU, https://pkg.go.dev, https://pkg.go.dev/vuln/GO-2022-1037, https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/2xxx/CVE-2022-2879.json, https://nvd.nist.gov/vuln/detail/CVE-2022-2879, https://security.gentoo.org/glsa/202311-09
Affected packages
Package
Name:
Purl:
