-
Notifications
You must be signed in to change notification settings - Fork 18.5k
Closed
Labels
FrozenDueToAgeNeedsFixThe path to resolution is known, but the work has not been done.The path to resolution is known, but the work has not been done.Securityrelease-blocker
Milestone
Description
Calling Glob on a path which contains a large number of path separators can cause a panic due to stack exhaustion.
This is CVE-2022-30630.
(This was a PRIVATE issue tracked in b/231318890 and fixed by http://tg/1497588.)
Metadata
Metadata
Assignees
Labels
FrozenDueToAgeNeedsFixThe path to resolution is known, but the work has not been done.The path to resolution is known, but the work has not been done.Securityrelease-blocker
Type
Projects
Status
Done