Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocate unbounded amounts of memory, potentially causing resource exhaustion or panics. After fix, Reader.Read limits the maximum size of header blocks to 1 MiB.

Project Subscriptions

Vendors Products
Container Native Virtualization Subscribe
Devtools Subscribe
Enterprise Linux Subscribe
Logging Subscribe
Openshift Subscribe
Openshift Api Data Protection Subscribe
Openshift Custom Metrics Autoscaler Subscribe
Openshift Data Foundation Subscribe
Openshift Serverless Subscribe
Openstack Subscribe
Rhosemc Subscribe
Serverless Subscribe
Service Interconnect Subscribe
Service Mesh Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-35111 Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocate unbounded amounts of memory, potentially causing resource exhaustion or panics. After fix, Reader.Read limits the maximum size of header blocks to 1 MiB.
Ubuntu USN Ubuntu USN USN-6038-1 Go vulnerabilities
Ubuntu USN Ubuntu USN USN-6038-2 Go vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 25 Feb 2025 02:00:00 +0000

Type Values Removed Values Added
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published:

Updated: 2025-02-13T16:32:38.510Z

Reserved: 2022-08-17T00:00:00.000Z

Link: CVE-2022-2879

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-10-14T15:15:17.647

Modified: 2024-11-21T07:01:51.487

Link: CVE-2022-2879

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-10-04T00:00:00Z

Links: CVE-2022-2879 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses