fix(deps): update module github.com/sigstore/cosign/v2 to v2.2.4 [security] - #7
Merged
yuzichen12123 merged 2 commits intoJul 24, 2025
Conversation
Author
ℹ Artifact update noticeFile name: go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
alaudaa-renovate
Bot
force-pushed
the
renovate/go-github.com-sigstore-cosign-v2-vulnerability
branch
5 times, most recently
from
July 23, 2025 15:18
781ac5f to
bd1f417
Compare
alaudaa-renovate
Bot
force-pushed
the
renovate/go-github.com-sigstore-cosign-v2-vulnerability
branch
from
July 23, 2025 15:31
bd1f417 to
6246d9b
Compare
Author
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
yuzichen12123
deleted the
renovate/go-github.com-sigstore-cosign-v2-vulnerability
branch
July 24, 2025 02:44
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v2.2.2->v2.2.4Cosign malicious artifacts can cause machine-wide DoS
BIT-cosign-2024-29903 / CVE-2024-29903 / GHSA-95pr-fxf5-86gv / GO-2024-2719
More information
Details
Maliciously-crafted software artifacts can cause denial of service of the machine running Cosign, thereby impacting all services on the machine. The root cause is that Cosign creates slices based on the number of signatures, manifests or attestations in untrusted artifacts. As such, the untrusted artifact can control the amount of memory that Cosign allocates.
As an example, these lines demonstrate the problem:
https://github.com/sigstore/cosign/blob/286a98a4a99c1b2f32f84b0d560e324100312280/pkg/oci/remote/signatures.go#L56-L70
This
Get()method gets the manifest of the image, allocates a slice equal to the length of the layers in the manifest, loops through the layers and adds a new signature to the slice.The exact issue is Cosign allocates excessive memory on the lines that creates a slice of the same length as the manifests.
Remediation
Update to the latest version of Cosign, where the number of attestations, signatures and manifests has been limited to a reasonable value.
Cosign PoC
In the case of this API (also referenced above):
https://github.com/sigstore/cosign/blob/286a98a4a99c1b2f32f84b0d560e324100312280/pkg/oci/remote/signatures.go#L56-L70
… The first line can contain a length that is safe for the system and will not throw a runtime panic or be blocked by other safety mechanisms. For the sake of argument, let’s say that the length of
m, err := s.Manifest()is the max allowed (by the machine without throwing OOM panics) manifests minus 1. When Cosign then allocates a new slice on this line:signatures := make([]oci.Signature, 0, len(m.Layers)), Cosign will allocate more memory than is available and the machine will be denied of service, causing Cosign and all other services on the machine to be unavailable.To illustrate the issue here, we run a modified version of
TestSignedImageIndex()inpkg/oci/remote:https://github.com/sigstore/cosign/blob/14795db16417579fac0c00c11e166868d7976b61/pkg/oci/remote/index_test.go#L31-L57
Here,
wantLayersis the number of manifests from these lines:https://github.com/sigstore/cosign/blob/286a98a4a99c1b2f32f84b0d560e324100312280/pkg/oci/remote/signatures.go#L56-L60
To test this, we want to make
wantLayershigh enough to not cause a memory on its own but still trigger the machine-wide OOM when a slice gets create with the same length. On my local machine, it would take hours to create a slice of layers that fulfils that criteria, so instead I modify the Cosign production code to reflect a long list of manifests:With this modified code, if we can cause an OOM without triggering the
panic("Done"), we have succeeded.Severity
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:HReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Cosign malicious attachments can cause system-wide denial of service in github.com/sigstore/cosign
BIT-cosign-2024-29902 / CVE-2024-29902 / GHSA-88jx-383q-w4qc / GO-2024-2718
More information
Details
Cosign malicious attachments can cause system-wide denial of service in github.com/sigstore/cosign
Severity
Unknown
References
This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).
Cosign malicious attachments can cause system-wide denial of service
BIT-cosign-2024-29902 / CVE-2024-29902 / GHSA-88jx-383q-w4qc / GO-2024-2718
More information
Details
Summary
A remote image with a malicious attachment can cause denial of service of the host machine running Cosign. This can impact other services on the machine that rely on having memory available such as a Redis database which can result in data loss. It can also impact the availability of other services on the machine that will not be available for the duration of the machine denial.
Details
The root cause of this issue is that Cosign reads the attachment from a remote image entirely into memory without checking the size of the attachment first. As such, a large attachment can make Cosign read a large attachment into memory; If the attachments size is larger than the machine has memory available, the machine will be denied of service. The Go runtime will make a
SIGKILLafter a few seconds of system-wide denial.The root cause is that Cosign reads the contents of the attachments entirely into memory on line 238 below:
https://github.com/sigstore/cosign/blob/9bc3ee309bf35d2f6e17f5d23f231a3d8bf580bc/pkg/oci/remote/remote.go#L228-L239
...and prior to that, neither Cosign nor go-containerregistry checks the size of the attachment and enforces a max cap. In the case of a remote layer of
f *attached, go-containerregistry will invoke this API:https://github.com/google/go-containerregistry/blob/a0658aa1d0cc7a7f1bcc4a3af9155335b6943f40/pkg/v1/remote/layer.go#L36-L40
Notice that the second argument to
rl.fetcher.fetchBlobisverify.SizeUnknownwhich results in not using theio.LimitReaderinverify.ReadCloser:https://github.com/google/go-containerregistry/blob/a0658aa1d0cc7a7f1bcc4a3af9155335b6943f40/internal/verify/verify.go#L82-L100
Impact
This issue can allow a supply-chain escalation from a compromised registry to the Cosign user: If an attacher has compromised a registry or the account of an image vendor, they can include a malicious attachment and hurt the image consumer.
Remediation
Update to the latest version of Cosign, which limits the number of attachments. An environment variable can override this value.
Severity
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:HReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Cosign malicious artifacts can cause machine-wide DoS in github.com/sigstore/cosign
BIT-cosign-2024-29903 / CVE-2024-29903 / GHSA-95pr-fxf5-86gv / GO-2024-2719
More information
Details
Cosign malicious artifacts can cause machine-wide DoS in github.com/sigstore/cosign
Severity
Unknown
References
This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).
Release Notes
sigstore/cosign (github.com/sigstore/cosign/v2)
v2.2.4Compare Source
Bug Fixes
Features
Documentation
Testing
v2.2.3Compare Source
Bug Fixes
Features
Documentation
versionsub-command expected behaviour documentation and testing (#3447)Misc
Contributors
Configuration
📅 Schedule: Branch creation - "" in timezone Asia/Shanghai, Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.