Out-of-memory vulnerability in github.com/libp2p/go-libp2p
Overview
Source
ID
GO-2023-2024
Aliases
CVE-2023-40583
GHSA-gcq9-qqwx-rgj3
Affected package
Description
A malicious actor can store an arbitrary amount of data in the memory of a remote node by sending the node a message with a signed peer record. Signed peer records from randomly generated peers can be sent by a malicious actor. This memory does not get garbage collected and so the remote node can run out of memory (OOM).
Summary
2.59k
Total packages affected
help_outline
Packages with at least one version that is affected by the advisory or has an affected dependency.
324
Packages with a known fix
help_outline
Packages with versions affected by the advisory that have a greater version that is not affected.
0.20%
Total ecosystem affected
help_outline
The proportion of packages in the ecosystem that are affected by the advisory (fixed or not).
Affected Version: Introduced: 0, Fixed: 0.27.4
Patched/Unaffected
Affected