⚠ Withdrawn by GitHub Security Advisories
Withdrawn: October 14, 2025
GHSA-q6gq-997w-f55gHighCVSS 7.5
Withdrawn Advisory: Infinite loop in xz
🔗 CVE IDs covered (1)
📋 Description
Withdrawn Advisory
This advisory has been withdrawn because alerts cannot be issued for the Go standard library at this time.
Original Description
Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs.
🎯 Affected products1
- go/github.com/ulikunitz/xz:< 0.5.8
🔗 References (19)
- https://nvd.nist.gov/vuln/detail/CVE-2020-16845
- https://github.com/ulikunitz/xz/issues/35
- https://github.com/ulikunitz/xz/commit/69c6093c7b2397b923acf82cb378f55ab2652b9b
- https://groups.google.com/forum/#!topic/golang-announce/NyPIaucMgXo
- https://groups.google.com/forum/#!topic/golang-announce/_ulYYcIWg3Q
- https://lists.debian.org/debian-lts-announce/2020/11/msg00037.html
- https://lists.debian.org/debian-lts-announce/2020/11/msg00038.html
- https://www.debian.org/security/2021/dsa-4848
- https://www.oracle.com/security-alerts/cpuApr2021.html
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00021.html
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00028.html
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00030.html
- https://lists.fedoraproject.org/archives/list/[email protected]/message/6RCFJTMKHY5ICGEM5BUFUEDDGSPJ25XU
- https://lists.fedoraproject.org/archives/list/[email protected]/message/KWRBAH4UZJO3RROQ72SYCUPFCJFA22FO
- https://lists.fedoraproject.org/archives/list/[email protected]/message/TACQFZDPA7AUR6TRZBCX2RGRFSDYLI7O
- https://lists.fedoraproject.org/archives/list/[email protected]/message/WV2VWKFTH4EJGZBZALVUJQJOAQB5MDQ4
- https://security.netapp.com/advisory/ntap-20200924-0002
- https://github.com/advisories/GHSA-q6gq-997w-f55g