packeto buildpacks vulnerable to CVE-2024-34156 (encoding/gob: stack exhaustion in Decoder.Decode) due to go 1.22.6 #308
Replies: 3 comments 3 replies
-
|
@candrews
When will the buildpacks to be updated to go 1.22.7 (or later) eliminating this vulnerability?
|
Beta Was this translation helpful? Give feedback.
-
|
@dmikusa you previously worked on a go issue I reported, could you please take a look at this one? |
Beta Was this translation helpful? Give feedback.
-
|
@anthonydahanne cut a release of the composite Java Buildpacks last night. Thanks for working through the pipeline issues!! 🙌 This should include new releases of all the composite Buildpacks which were build with the latest Go version. tl;dr this should clear up the latest list of Go CVEs being reported against the Java Buildpacks. Please let me know if you're still seeing any after updating. Thanks! |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
I noticed that many Paketo Buildpacks projects use go 1.22.6 which is susceptible to CVE-2024-34156: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This raises two questions:
I don't believe it's exploitable, but an statement/assessment from Paketo would be helpful.
Thank you!
Trivy can be used to see this vulnerability being reported:
Beta Was this translation helpful? Give feedback.
All reactions