Vulnerability Report: GO-2023-1573
- CVE-2023-25153, GHSA-259w-8hf6-59c2
- Affects: github.com/containerd/containerd
- Published: Feb 17, 2023
- Modified: Aug 21, 2024
When importing an OCI image, there was no limit on the number of bytes read from the io.Reader passed into ImportIndex. A large number of bytes could be read from this and could cause a denial of service.
For detailed information about this vulnerability, visit https://github.com/containerd/containerd/security/advisories/GHSA-259w-8hf6-59c2.
Affected Packages
-
PathGo VersionsSymbols
-
before v1.5.18, from v1.6.0 before v1.6.18
Aliases
References
- https://github.com/containerd/containerd/security/advisories/GHSA-259w-8hf6-59c2
- https://github.com/containerd/containerd/commit/0c314901076a74a7b797a545d2f462285fdbb8c4
- https://github.com/containerd/containerd/releases/tag/v1.5.18
- https://github.com/containerd/containerd/releases/tag/v1.6.18
- https://vuln.go.dev/ID/GO-2023-1573.json
Credits
- @AdamKorcz, @DavidKorczynski
Feedback
See anything missing or incorrect?
Suggest an edit to this report.