{"id":"GHSA-q3j6-22wf-3jh9","summary":"github.com/ipfs/go-bitswap vulnerable to DOS unbounded persistent memory leak","details":"This package has been moved to [`github.com/ipfs/boxo/bitswap`](https://pkg.go.dev/github.com/ipfs/boxo/bitswap), this vulnerability is tracked there: https://github.com/ipfs/boxo/security/advisories/GHSA-m974-xj4j-7qv5 (`CVE-2023-25568`)\n\n### Remediation\nThis is a two step process:\n1. Apply one of:\n   - (**recommended**) upgrade from `github.com/ipfs/go-bitswap` to `github.com/ipfs/boxo/bitswap`.\n   - If you are still using `github.com/ipfs/go-bitswap` and cannot upgrade to `boxo`, you can upgrade to `github.com/ipfs/go-bitswap@v0.12.0`, this will replace the `go-bitswap` implementation by stubs which points to `boxo`.\n2. Open https://github.com/ipfs/boxo/security/advisories/GHSA-m974-xj4j-7qv5 and then follow `boxo`'s remediation section.\n\n### Vulnerable symbols\n- `\u003e= v0.9.0; \u003c v0.12.0`\n  - `github.com/ipfs/go-bitswap/server/internal/decision.(*Engine).MessageReceived`\n  - `github.com/ipfs/go-bitswap/server/internal/decision.(*Engine).NotifyNewBlocks`\n  - `github.com/ipfs/go-bitswap/server/internal/decision.(*Engine).findOrCreate`\n  - `github.com/ipfs/go-bitswap/server/internal/decision.(*Engine).PeerConnected`\n- `v0.8.0`\n  - `github.com/ipfs/go-bitswap/internal/decision.(*Engine).MessageReceived`\n  - `github.com/ipfs/go-bitswap/internal/decision.(*Engine).NotifyNewBlocks`\n  - `github.com/ipfs/go-bitswap/internal/decision.(*Engine).findOrCreate`\n  - `github.com/ipfs/go-bitswap/internal/decision.(*Engine).PeerConnected`\n- `\u003c v0.8.0`\n  - `github.com/ipfs/go-bitswap/internal/decision.(*Engine).MessageReceived`\n  - `github.com/ipfs/go-bitswap/internal/decision.(*Engine).receiveBlocksFrom`\n  - `github.com/ipfs/go-bitswap/internal/decision.(*Engine).findOrCreate`\n  - `github.com/ipfs/go-bitswap/internal/decision.(*Engine).PeerConnected`\n\n### Workarounds\nIf you are using the stubs at `github.com/ipfs/go-bitswap` and not taking advantage of the features provided by the server, refactoring your code to use the new split API will allows you to run in a client-only mode using: [`github.com/ipfs/go-bitswap/client`](https://pkg.go.dev/github.com/ipfs/go-bitswap/client).","aliases":["CVE-2023-25568","GHSA-m974-xj4j-7qv5","GO-2023-1766"],"modified":"2023-11-08T04:11:52.109563Z","published":"2023-05-11T20:39:55Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-05-11T20:39:55Z","nvd_published_at":null,"cwe_ids":["CWE-400","CWE-770"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/ipfs/boxo/security/advisories/GHSA-m974-xj4j-7qv5"},{"type":"WEB","url":"https://github.com/ipfs/go-bitswap/security/advisories/GHSA-q3j6-22wf-3jh9"},{"type":"WEB","url":"https://github.com/ipfs/go-libipfs/security/advisories/GHSA-m974-xj4j-7qv5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-25568"},{"type":"WEB","url":"https://github.com/ipfs/boxo/commit/62cbac40b96f49e39cd7fedc77ee6b56adce4916"},{"type":"WEB","url":"https://github.com/ipfs/boxo/commit/9cb5cb54d40b57084d1221ba83b9e6bb3fcc3197"},{"type":"PACKAGE","url":"https://github.com/ipfs/go-bitswap"}],"affected":[{"package":{"name":"github.com/ipfs/go-bitswap","ecosystem":"Go","purl":"pkg:golang/github.com/ipfs/go-bitswap"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.12.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/05/GHSA-q3j6-22wf-3jh9/GHSA-q3j6-22wf-3jh9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}