-
Notifications
You must be signed in to change notification settings - Fork 18.4k
Closed
Labels
FrozenDueToAgeNeedsFixThe path to resolution is known, but the work has not been done.The path to resolution is known, but the work has not been done.Securityrelease-blocker
Milestone
Description
Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion.
This is CVE-2022-30635.
(This was a PRIVATE issue tracked in http://b/231318421 and fixed by http://tg/1484771.)
/cc https://github.com/orgs/golang/teams/security and https://github.com/orgs/golang/teams/release
dmitshur
Metadata
Metadata
Assignees
Labels
FrozenDueToAgeNeedsFixThe path to resolution is known, but the work has not been done.The path to resolution is known, but the work has not been done.Securityrelease-blocker
Type
Projects
Status
Done