Due to a goroutine deadlock, using github.com/containers/storage/pkg/archive.DecompressStream on a xz archive returns a reader which will hang indefinitely when Close is called. An attacker can use this to cause denial of service if they are able to cause the caller to attempt to decompress an archive they control.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2021-0100" }
{ "imports": [ { "path": "github.com/containers/storage/pkg/archive", "symbols": [ "ApplyLayer", "ApplyUncompressedLayer", "Archiver.CopyFileWithTar", "Archiver.CopyWithTar", "Archiver.TarUntar", "Archiver.UntarPath", "CopyResource", "CopyTo", "DecompressStream", "IsArchivePath", "Untar", "UntarPath", "UntarUncompressed", "cmdStream" ] } ] }