CVE-2024-34158 Information

Description

Calling Parse on a // +build\ build tag line with deeply nested expressions can cause a panic due to stack exhaustion.

Reference

https://go.dev/cl/611240 https://go.dev/issue/69141 https://groups.google.com/g/golang-dev/c/S9POB9NCTdk https://pkg.go.dev/vuln/GO-2024-3107

Share on: