Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 931602 (CVE-2024-24788) - <dev-lang/go-{1.21.10,1.22.3}: malformed DNS message can cause infinite loop
Summary: <dev-lang/go-{1.21.10,1.22.3}: malformed DNS message can cause infinite loop
Status: CONFIRMED
Alias: CVE-2024-24788
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://groups.google.com/g/golang-an...
Whiteboard: A3 [stable]
Keywords:
Depends on: 931843
Blocks:
  Show dependency tree
 
Reported: 2024-05-08 20:21 UTC by Christopher Fore
Modified: 2024-05-13 04:47 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Christopher Fore 2024-05-08 20:21:34 UTC
CVE-2024-24788:

A malformed DNS message in response to a query can cause the Lookup functions to get stuck in an infinite loop.



The above is fixed in 1.22.3 and 1.21.10.