golang.org/x/text/language in golang.org/x/text before 0.3.7 can panic with an out-of-bounds read during BCP 47 language tag parsing. Index calculation is mishandled. If parsing untrusted user input, this can be used as a vector for a denial-of-service attack.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "0.0~git20170627.0.6353ef0-1ubuntu2.1", "binary_name": "golang-golang-x-text-dev" }, { "binary_version": "0.0~git20170627.0.6353ef0-1ubuntu2.1", "binary_name": "golang-x-text-dev" } ] }