]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core-contrib.git/commit
go: Fix CVE-2024-34156
authorArchana Polampalli <archana.polampalli@windriver.com>
Wed, 8 Jan 2025 05:54:20 +0000 (05:54 +0000)
committerSteve Sakoman <steve@sakoman.com>
Tue, 14 Jan 2025 13:49:41 +0000 (05:49 -0800)
commit3aeeee86a53cee14bb1a6a485f8781459b6f2ffc
tree7e473b576afa030466df14607c6f3f2180a93f36
parent9d21d527e2448e202030ae7ad38c88e25943a2f3
go: Fix CVE-2024-34156

Calling Decoder.Decode on a message which contains deeply nested structures can
cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.

Reference:
https://nvd.nist.gov/vuln/detail/CVE-2024-34156

Upstream-patch:
https://github.com/golang/go/commit/2092294f2b097c5828f4eace6c98a322c1510b01

Signed-off-by: Archana Polampalli <archana.polampalli@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/recipes-devtools/go/go-1.17.13.inc
meta/recipes-devtools/go/go-1.21/CVE-2024-34156.patch [new file with mode: 0644]