-
Notifications
You must be signed in to change notification settings - Fork 17.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
x/image/tiff: over allocation in DecodeConfig (CVE-2022-41727) #58003
Comments
@gopherbot please open backport issues. |
Backport issue(s) opened: #58403 (for 1.19), #58404 (for 1.20). Remember to create the cherry-pick CL(s) as soon as the patch is submitted to master, according to https://go.dev/wiki/MinorReleases. |
This change will not be backported, as it is a change to a golang.org/x/ module which is not vendored in the standard library. |
Change https://go.dev/cl/468195 mentions this issue: |
Does this warrant reconsidering #20814 |
This is a PRIVATE issue for CVE-2022-41727, tracked in http://b/262244452 and fixed by http://tg/1680712.
/cc @golang/security and @golang/release
The text was updated successfully, but these errors were encountered: