Intel

AIKIDO-2024-10252

go.opentelemetry.io/collector/component is vulnerable to Deadlock

Deadlock Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Sep 11, 2024

20

Low Risk

This Affects:

gogo.opentelemetry.io/collector/component
0.100.0 - 0.108.1
Fixed in 0.109.0
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to a potential deadlock in the persistent queue due to a race condition, where the used value in sizedChannel becomes out of sync with the channel length.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

go.opentelemetry.io/collector/component is vulnerable to Deadlock in versions 0.100.0 - 0.108.1.

How to fix this

Upgrade the go.opentelemetry.io/collector/component library to the patch version.