PT-2026-84861 · Azure Linux+7 · Buildah+33

·

CVE-2026-78662

·

Publicado

2026-09-02

·

Atualizado

2026-09-09

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Nome do Software Vulnerável e Versões Afetadas O nome do produto não pôde ser determinado. (versões afetadas não especificadas)
Descrição Existe uma falha onde um canal registrado no chanList do mux permanece inutilizável até que seja estabelecido. Um peer malicioso pode inundar o incomingRequests do canal, levando a um deadlock de toda a conexão. Isso ocorre porque o sistema não lida adequadamente com os pacotes antes que o canal atinja um estado estabelecido.
Recomendações No momento, não há informações sobre uma versão mais recente que contenha a correção para esta vulnerabilidade.

Exploit

DoS

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

AZL-99126
AZL-99129
AZL-99144
AZL-99156
AZL-99165
AZL-99195
AZL-99207
AZL-99225
AZL-99249
AZL-99261
AZL-99273
AZL-99285
AZL-99312
AZL-99321
AZL-99384
CVE-2026-78662
GO-2026-6354
OPENSUSE-SU-2026:11727-1
OPENSUSE-SU-2026:21801-1
OPENSUSE-SU-2026:21812-1
OPENSUSE-SU-2026:21814-1
OPENSUSE-SU-2026:21816-1
OPENSUSE-SU-2026:21824-1

Produtos afetados

Buildah
Cert-Manager
Cf Cli
Containerized-Data-Importer-1.65
Cri-O
Crypto++
Docker Buildx
Docker Compose
Gh
Golang-1.17
Golang-1.20
Golang-1.21
Golang-1.22
Golang-1.23
Golang-1.24
Golang-1.25
Golang-1.26
Golang-Defaults
Golang-Go.Crypto
Golang.Org/X/Crypto
Golang.Org/X/Crypto/Ssh
Govulncheck-Vulndb
Hauler
Kubernetes
Kubevirt
Containers/Common
Moby-Engine
Nvidia Container Toolkit
Packer
Podman
Rclone
Telegraf
Trivy
Zk