Withdrawn Advisory: Infinite loop in xz
High severity
GitHub Reviewed
Published
Dec 16, 2021
to the GitHub Advisory Database
•
Updated Oct 14, 2025
Withdrawn
This advisory was withdrawn on Oct 14, 2025
Description
Published by the National Vulnerability Database
Aug 6, 2020
Reviewed
Jun 18, 2021
Published to the GitHub Advisory Database
Dec 16, 2021
Withdrawn
Oct 14, 2025
Last updated
Oct 14, 2025
Withdrawn Advisory
This advisory has been withdrawn because alerts cannot be issued for the Go standard library at this time.
Original Description
Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs.
References