ipfs / kubo

An IPFS implementation in Go
https://docs.ipfs.tech/how-to/command-line-quick-start/
Other
15.81k stars 2.96k forks source link

CVE-2024-22189 quic-go: memory exhaustion attack #10389

Closed bmwiedemann closed 3 weeks ago

bmwiedemann commented 4 weeks ago

Checklist

Installation method

built from source

Version

0.27.0

Config

No response

Description

In https://bugzilla.opensuse.org/show_bug.cgi?id=1222479 our security team made me aware of a security issue in the quic-go version used in kubo.

Stebalien commented 3 weeks ago

The just-released v0.28 includes the fix: https://github.com/ipfs/kubo/releases/tag/v0.28.0