Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-2879
HistoryOct 14, 2022 - 3:15 p.m.

Design/Logic Flaw

2022-10-1415:15:00
PRIOn knowledge base
www.prio-n.com
9
reader.read
memory allocation
header block size
fix
resource exhaustion
nvd

7.4 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

59.0%

Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocate unbounded amounts of memory, potentially causing resource exhaustion or panics. After fix, Reader.Read limits the maximum size of header blocks to 1 MiB.

CPENameOperatorVersion
goge1.19.0
golt1.19.2
golt1.18.7