GHSA-53c4-hhmh-vw5q
Dashboard / Vulnerabilities / GHSA-53c4-hhmh-vw5q
GHSA-53c4-hhmh-vw5q
Summary: Helm vulnerable to denial of service through through repository index file
Details: Fuzz testing, by Ada Logics and sponsored by the CNCF, identified input to functions in the `_repo_` package that can cause a segmentation violation. Applications that use functions from the `_repo_` package in the Helm SDK can have a Denial of Service attack when they use this package and it panics. ### Impact The `_repo_` package contains a handler that processes the index file of a repository. For example, the Helm client adds references to chart repositories where charts are managed. The `_repo_` package parses the index file of the repository and loads it into structures Go can work with. Some index files can cause array data structures to be created causing a memory violation. Applications that use the `_repo_` package in the Helm SDK to parse an index file can suffer a Denial of Service when that input causes a panic that cannot be recovered from. The Helm Client will panic with an index file that causes a memory violation panic. Helm is not a long running service so the panic will not affect future uses of the Helm client. ### Patches This issue has been resolved in 3.10.3. ### Workarounds SDK users can validate index files that are correctly formatted before passing them to the `_repo_` functions. ### For more information Helm's security policy is spelled out in detail in our [SECURITY](https://github.com/helm/community/blob/master/SECURITY.md) document. ### Credits Disclosed by Ada Logics in a fuzzing audit sponsored by CNCF.
References: https://github.com/helm/helm/security/advisories/GHSA-53c4-hhmh-vw5q, https://nvd.nist.gov/vuln/detail/CVE-2022-23525, https://github.com/helm/helm/commit/638ebffbc2e445156f3978f02fd83d9af1e56f5b, https://github.com/helm/helm, https://pkg.go.dev/vuln/GO-2022-1165
Affected packages
Package
Name: helm.sh/helm/v3
Purl: pkg:golang/helm.sh/helm/v3
Affected ranges
Type: SEMVER
Events:
