HomeDefault status
unaffected
Any version before 1.25.10
affected
1.26.0-0 (semver) before 1.26.3
affected
Description
When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.
Problem types
Product status
Any version before 1.25.10
1.26.0-0 (semver) before 1.26.3
Credits
hamayanhamayan
References
groups.google.com/g/golang-announce/c/qcCIEXso47M