NULL Pointer Dereference Affecting github.com/helm/helm/pkg/chartutil package, versions <3.10.3
Threat Intelligence
EPSS
0.09% (41st
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-GOLANG-GITHUBCOMHELMHELMPKGCHARTUTIL-3172916
- published 15 Dec 2022
- disclosed 14 Dec 2022
- credit DavidKorczynski, AdamKorcz
Introduced: 14 Dec 2022
CVE-2022-23526 Open this link in a new tabHow to fix?
Upgrade github.com/helm/helm/pkg/chartutil
to version 3.10.3 or higher.
Overview
github.com/helm/helm/pkg/chartutil is a package manager for kubernetes.
Affected versions of this package are vulnerable to NULL Pointer Dereference due to accepting input to functions that can cause a segmentation violation. Some schema files can cause array data structures to be created causing a memory violation.
Workaround
SDK users can validate schema files that are correctly formatted before passing them to the chartutil
functions.
References
CVSS Scores
version 3.1