Description
Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocate unbounded amounts of memory, potentially causing resource exhaustion or panics. After fix, Reader.Read limits the maximum size of header blocks to 1 MiB.
Published: 2022-10-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-35111 Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocate unbounded amounts of memory, potentially causing resource exhaustion or panics. After fix, Reader.Read limits the maximum size of header blocks to 1 MiB.
Ubuntu USN Ubuntu USN USN-6038-1 Go vulnerabilities
Ubuntu USN Ubuntu USN USN-6038-2 Go vulnerabilities
History

Tue, 25 Feb 2025 02:00:00 +0000

Type Values Removed Values Added
References

Subscriptions

Golang Go
Redhat Container Native Virtualization Devtools Enterprise Linux Logging Openshift Openshift Api Data Protection Openshift Custom Metrics Autoscaler Openshift Data Foundation Openshift Serverless Openstack Rhmt Rhosemc Serverless Service Interconnect Service Mesh
cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published:

Updated: 2025-02-13T16:32:38.510Z

Reserved: 2022-08-17T00:00:00.000Z

Link: CVE-2022-2879

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-10-14T15:15:17.647

Modified: 2024-11-21T07:01:51.487

Link: CVE-2022-2879

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-10-04T00:00:00Z

Links: CVE-2022-2879 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses