Описание
Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
golang-1.23 | fixed | 1.23.1-1 | package | |
golang-1.22 | fixed | 1.22.7-1 | package | |
golang-1.21 | unfixed | package | ||
golang-1.19 | removed | package | ||
golang-1.19 | no-dsa | bookworm | package | |
golang-1.15 | removed | package | ||
golang-1.15 | postponed | bullseye | package |
Примечания
https://groups.google.com/g/golang-announce/c/K-cEzDeCtpc
https://go.dev/issue/69141
https://github.com/golang/go/commit/032ac075c20c01c6c35a672d1542d3e98eab84ea (go1.23.1)
https://github.com/golang/go/commit/d4c53812e6ce2ac368173d7fcd31d0ecfcffb002 (go1.22.7)
EPSS
Связанные уязвимости
Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion.
Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion.
Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion.
Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion.
Уязвимость функции Parse языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании
EPSS