GO-2022-0247
Dashboard / Vulnerabilities / GO-2022-0247
GO-2022-0247
Summary: Buffer overflow in WASM modules in misc/wasm and cmd/link
Details: When invoking functions from WASM modules, built using GOARCH=wasm GOOS=js, passing very large arguments can cause portions of the module to be overwritten with data from the arguments due to a buffer overflow error. If using wasm_exec.js to execute WASM modules, users will need to replace their copy (as described in https://golang.org/wiki/WebAssembly#getting-started) after rebuilding any modules.
References: https://go.dev/cl/354571, https://go.googlesource.com/go/+/77f2750f4398990eed972186706f160631d7dae4, https://go.dev/issue/48797, https://groups.google.com/g/golang-announce/c/AEBu9j7yj5A
Affected packages
Package
Name: toolchain
Purl: pkg:golang/toolchain
Affected ranges
Type: SEMVER
Events:
