Skip to content

encoding/pem: stack overflow #51853

@julieqiu

Description

@julieqiu

A large (more than 5 MB) PEM input can cause a stack overflow in Decode, leading the program to crash.

Thanks to Juho Nurminen of Mattermost who reported the error.

This is CVE-2022-24675.

(This was a PRIVATE issue tracked in http://b/216105673 and fixed by http://tg/1391157.)

/cc @golang/security and @golang/release

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions