Skip to content

DOS HAMT Decoding Panics

Moderate
Jorropo published GHSA-4gj3-6r43-3wfc Feb 9, 2023

Package

gomod github.com/ipfs/go-unixfsnode (Go)

Affected versions

< 1.5.2

Patched versions

1.5.2

Description

Impact

Trying to read malformed HAMT sharded directories can cause panics and virtual memory leaks.
If you are reading untrusted user input, an attacker can then trigger a panic.

This is caused by bogus fanout parameter in the HAMT directory nodes.
This include checks returned in ipfs/go-bitfield GHSA-2h6c-j3gf-xp9r, as well as limiting the fanout to <= 1024 (to avoid attempts of arbitrary sized allocations).

Patches

References

Severity

Moderate

CVE ID

CVE-2023-23631

Weaknesses

No CWEs

Credits