CVE-2023-23625: Denial of service in HAMT Decoding in go-unixfs
Impact Trying to read malformed HAMT sharded directories can cause panics and virtual memory leaks. If you are reading untrusted user input, an attacker can then trigger a panic.
This is caused by bogus fanout parameter in the HAMT directory nodes. This include checks returned in ipfs/go-bitfield GHSA-2h6c-j3gf-xp9r, as well as limiting the fanout to <= 1024 (to avoid attempts of arbitrary sized allocations).
Patches - https://github.com/ipfs/go-unixfs/commit/dbcc43ec3e2db0d01e8d80c55040bba3cf22cb4b
Workarounds Do not feed untrusted user data to the decoding functions.
References - https://github.com/ipfs/go-bitfield/security/advisories/GHSA-2h6c-j3gf-xp9r
Other sources
go-unixfs is an implementation of a unix-like filesystem on top of an ipld merkledag. Trying to read malformed HAMT sharded directories can cause panics and virtual memory leaks. If you are reading untrusted user input, an attacker can then trigger a panic. This is caused by bogus fanout parameter in the HAMT directory nodes. Users are advised to upgrade to version 0.4.3 to resolve this issue. Users unable to upgrade should not feed untrusted user data to the decoding functions.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-23625?
CVE-2023-23625 is a vulnerability in the go-unixfs library that can be exploited by reading malformed HAMT sharded directories, leading to panics and virtual memory leaks.
What is the severity of CVE-2023-23625?
CVE-2023-23625 has a severity rating of high with a CVSS score of 7.5.
How does CVE-2023-23625 affect go-unixfs?
CVE-2023-23625 affects go-unixfs versions up to and excluding version 0.4.3.
Can CVE-2023-23625 be exploited remotely?
No, the vulnerability requires reading malformed HAMT sharded directories, which means it can only be exploited by a local attacker.
How can I mitigate CVE-2023-23625?
To mitigate CVE-2023-23625, update go-unixfs to a version that is equal to or higher than 0.4.3.