Vulnerability Report: GO-2023-1559

Trying to read malformed HAMT sharded directories can cause panics and virtual memory leaks. If you are reading untrusted user input, an attacker can then trigger a panic. This is caused by a bogus fanout parameter in the HAMT directory nodes. There are no known workarounds (users are advised to upgrade).

For detailed information about this vulnerability, visit https://github.com/ipfs/go-unixfsnode/security/advisories/GHSA-4gj3-6r43-3wfc.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL