PT-2026-84853 · Azure Linux+7 · Buildah+37

·

CVE-2026-56855

·

Publicado

2026-09-02

·

Atualizado

2026-09-11

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Nome do Software Vulnerável e Versões Afetadas O nome do produto não pôde ser determinado (versões afetadas não especificadas)
Descrição Um peer malicioso pode enviar mensagens manipuladas após o estabelecimento de um canal para causar um deadlock de toda a conexão. Isso ocorre porque o sistema armazena em buffer e bloqueia em vez de tratar mensagens inesperadas como erros de protocolo.
Recomendações No momento, não há informações sobre uma versão mais recente que contenha a correção para esta vulnerabilidade.

Exploit

DoS

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

AZL-99123
AZL-99135
AZL-99147
AZL-99159
AZL-99168
AZL-99198
AZL-99210
AZL-99222
AZL-99255
AZL-99264
AZL-99270
AZL-99282
AZL-99309
AZL-99318
AZL-99381
CVE-2026-56855
GO-2026-6355
OPENSUSE-SU-2026:11685-1
OPENSUSE-SU-2026:11691-1
OPENSUSE-SU-2026:11698-1
OPENSUSE-SU-2026:11704-1
OPENSUSE-SU-2026:11717-1
OPENSUSE-SU-2026:11727-1
OPENSUSE-SU-2026:11731-1
OPENSUSE-SU-2026:11732-1
OPENSUSE-SU-2026:11752-1
OPENSUSE-SU-2026:21801-1
OPENSUSE-SU-2026:21812-1
OPENSUSE-SU-2026:21814-1
OPENSUSE-SU-2026:21816-1
OPENSUSE-SU-2026:21824-1

Produtos afetados

Buildah
Cert-Manager
Cf Cli
Containerized-Data-Importer-1.65
Containerized-Data-Importer1.66
Cri-O
Crypto++
Docker Buildx
Docker Compose
Gh
Git-Bug
Golang-1.17
Golang-1.20
Golang-1.21
Golang-1.22
Golang-1.23
Golang-1.24
Golang-1.25
Golang-1.26
Golang-Defaults
Golang-Go.Crypto
Golang.Org/X/Crypto
Golang.Org/X/Crypto/Ssh
Govulncheck-Vulndb
Hauler
Keybase Client
Kubernetes
Kubevirt
Kubevirt1.9
Containers/Common
Moby-Engine
Nvidia Container Toolkit
Packer
Podman
Rclone
Telegraf
Trivy
Zk