packeto buildpacks vulnerable to CVE-2024-34156 (encoding/gob: stack exhaustion in Decoder.Decode) due to go 1.22.6 #308
Replies: 3 comments 3 replies
-
@candrews
When will the buildpacks to be updated to go 1.22.7 (or later) eliminating this vulnerability?
|
Beta Was this translation helpful? Give feedback.
-
@dmikusa you previously worked on a go issue I reported, could you please take a look at this one? |
Beta Was this translation helpful? Give feedback.
-
@anthonydahanne cut a release of the composite Java Buildpacks last night. Thanks for working through the pipeline issues!! 🙌 This should include new releases of all the composite Buildpacks which were build with the latest Go version. tl;dr this should clear up the latest list of Go CVEs being reported against the Java Buildpacks. Please let me know if you're still seeing any after updating. Thanks! |
Beta Was this translation helpful? Give feedback.
-
I noticed that many Paketo Buildpacks projects use go 1.22.6 which is susceptible to CVE-2024-34156: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This raises two questions:
I don't believe it's exploitable, but an statement/assessment from Paketo would be helpful.
Thank you!
Trivy can be used to see this vulnerability being reported:
Beta Was this translation helpful? Give feedback.
All reactions