Uncontrolled recursion in Reader.Read in compress/gzip before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via an archive containing a large number of concatenated 0-length compressed files.
{
"binaries": [
{
"binary_version": "1.18.1-1ubuntu1~18.04.4",
"binary_name": "golang-1.18"
},
{
"binary_version": "1.18.1-1ubuntu1~18.04.4",
"binary_name": "golang-1.18-go"
},
{
"binary_version": "1.18.1-1ubuntu1~18.04.4",
"binary_name": "golang-1.18-src"
}
],
"availability": "No subscription required"
}{
"binaries": [
{
"binary_version": "1.13.8-1ubuntu1.2",
"binary_name": "golang-1.13"
},
{
"binary_version": "1.13.8-1ubuntu1.2",
"binary_name": "golang-1.13-go"
},
{
"binary_version": "1.13.8-1ubuntu1.2",
"binary_name": "golang-1.13-src"
}
],
"availability": "No subscription required"
}{
"binaries": [
{
"binary_version": "1.16.2-0ubuntu1~20.04.1",
"binary_name": "golang-1.16"
},
{
"binary_version": "1.16.2-0ubuntu1~20.04.1",
"binary_name": "golang-1.16-go"
},
{
"binary_version": "1.16.2-0ubuntu1~20.04.1",
"binary_name": "golang-1.16-src"
}
],
"availability": "No subscription required"
}{
"binaries": [
{
"binary_version": "1.18.1-1ubuntu1~20.04.2",
"binary_name": "golang-1.18"
},
{
"binary_version": "1.18.1-1ubuntu1~20.04.2",
"binary_name": "golang-1.18-go"
},
{
"binary_version": "1.18.1-1ubuntu1~20.04.2",
"binary_name": "golang-1.18-src"
}
],
"availability": "No subscription required"
}{
"binaries": [
{
"binary_version": "1.13.8-1ubuntu2.22.04.2",
"binary_name": "golang-1.13"
},
{
"binary_version": "1.13.8-1ubuntu2.22.04.2",
"binary_name": "golang-1.13-go"
},
{
"binary_version": "1.13.8-1ubuntu2.22.04.2",
"binary_name": "golang-1.13-src"
}
],
"availability": "No subscription required"
}{
"binaries": [
{
"binary_version": "1.18.1-1ubuntu1.1",
"binary_name": "golang-1.18"
},
{
"binary_version": "1.18.1-1ubuntu1.1",
"binary_name": "golang-1.18-go"
},
{
"binary_version": "1.18.1-1ubuntu1.1",
"binary_name": "golang-1.18-src"
}
],
"availability": "No subscription required"
}{
"binaries": [
{
"binary_version": "1.13.8-1ubuntu1~16.04.3+esm3",
"binary_name": "golang-1.13"
},
{
"binary_version": "1.13.8-1ubuntu1~16.04.3+esm3",
"binary_name": "golang-1.13-go"
},
{
"binary_version": "1.13.8-1ubuntu1~16.04.3+esm3",
"binary_name": "golang-1.13-src"
}
],
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}{
"binaries": [
{
"binary_version": "1.13.8-1ubuntu1~18.04.4+esm1",
"binary_name": "golang-1.13"
},
{
"binary_version": "1.13.8-1ubuntu1~18.04.4+esm1",
"binary_name": "golang-1.13-go"
},
{
"binary_version": "1.13.8-1ubuntu1~18.04.4+esm1",
"binary_name": "golang-1.13-src"
}
],
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}{
"binaries": [
{
"binary_version": "1.16.2-0ubuntu1~18.04.2+esm1",
"binary_name": "golang-1.16"
},
{
"binary_version": "1.16.2-0ubuntu1~18.04.2+esm1",
"binary_name": "golang-1.16-go"
},
{
"binary_version": "1.16.2-0ubuntu1~18.04.2+esm1",
"binary_name": "golang-1.16-src"
}
],
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}