{"id":"GO-2023-1559","summary":"Denial of service via HAMT decoding panic in github.com/ipfs/go-unixfsnode","details":"Trying to read malformed HAMT sharded directories can cause panics and virtual memory leaks. If you are reading untrusted user input, an attacker can then trigger a panic.\n\nThis is caused by a bogus fanout parameter in the HAMT directory nodes.\n\nThere are no known workarounds (users are advised to upgrade).","aliases":["CVE-2023-23631","GHSA-4gj3-6r43-3wfc"],"modified":"2024-05-20T16:03:47Z","published":"2023-02-14T19:41:30Z","database_specific":{"url":"https://pkg.go.dev/vuln/GO-2023-1559","review_status":"REVIEWED"},"references":[{"type":"ADVISORY","url":"https://github.com/ipfs/go-unixfsnode/security/advisories/GHSA-4gj3-6r43-3wfc"},{"type":"FIX","url":"https://github.com/ipfs/go-unixfsnode/commit/59050ea8bc458ae55246ae09243e6e165923e076"}],"affected":[{"package":{"name":"github.com/ipfs/go-unixfsnode","ecosystem":"Go","purl":"pkg:golang/github.com/ipfs/go-unixfsnode"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.5.2"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/ipfs/go-unixfsnode/hamt","symbols":["AttemptHAMTShardFromNode","NewUnixFSHAMTShard","NewUnixFSHAMTShardWithPreload","_UnixFSHAMTShard.Length","_UnixFSHAMTShard.Lookup","_UnixFSHAMTShard.LookupByNode","_UnixFSHAMTShard.LookupBySegment","_UnixFSHAMTShard.LookupByString","_UnixFSShardedDir__ListItr.Next","bitField"]},{"path":"github.com/ipfs/go-unixfsnode/data/builder","symbols":["BlockSizes","BuildUnixFS","BuildUnixFSDirectory","BuildUnixFSFile","BuildUnixFSRecursive","BuildUnixFSShardedDirectory","BuildUnixFSSymlink","Data","DataType","Fanout","FileSize","FractionalNanoseconds","HashType","Mtime","Permissions","PermissionsString","Seconds","Time","shard.bitmap","shard.serialize"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2023-1559.json"}}],"schema_version":"1.7.3","credits":[{"name":"Jorropo"}]}