Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-46603

Опубликовано: 14 авг. 2026
Источник: debian

Описание

VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-golang-x-imagefixed0.45.0-1package
golang-golang-x-imageno-dsatrixiepackage
golang-golang-x-imagepostponedbookwormpackage
golang-golang-x-imagepostponedbullseyepackage

Примечания

  • https://github.com/golang/go/issues/80069

  • Fixed by: https://github.com/golang/image/commit/981eaa05a5065f5dd09c3139029c0d7dbda956d8 (v0.45.0)

Связанные уязвимости

CVSS3: 7.5
ubuntu
25 дней назад

VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion.

CVSS3: 7.5
redhat
25 дней назад

VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion.

CVSS3: 7.5
nvd
25 дней назад

VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion.