PT-2026-42717 · Opensuse+11 · Alloy+88
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
The product name cannot be determined (affected versions not specified)
Description
An incorrectly placed cast from bytes to int in the AES-GCM packet decoder allows for a server-side panic when processing well-crafted inputs. A server-side panic is a critical error that causes the application to crash unexpectedly.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Incorrect Type Conversion or Cast
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alloy
Amazon-Ssm-Agent
Apko
Apptainer
Argo Cd
Argo Workflows
Buildah
Cadvisor
Calico
Calicoctl
Cert-Manager
Cf Cli
Cilium-Cli
Hashicorp Consul
Kubernetes Containerd
Cortex
Cosign
Cri-O
Crypto++
Distribution
Docker Buildx
Docker-Cli-Buildx
Docker Compose
Elastic-Beats
Elemental-Toolkit
Etcd
External-Secrets
Gh
Git-Bug
Glab
Golang-Go.Crypto
Golang.Org/X/Crypto
Golang.Org/X/Crypto/Ssh
Google-Guest-Agent
Google-Osconfig-Agent
Gostatsd
Govulncheck-Vulndb
Grype
Haproxy-Ingress
Hauler
Helm
Helm-Operator
Istio
Kube-State-Metrics
Kube-Vip
Kubernetes
Kubernetes-Csi-External-Provisioner-Fips
Kubernetes-Csi-External-Snapshotter-Fips
Kubevirt
Kubevirt-1.8
Lxd
Mcphost
Memcached-Exporter
Moby-Engine
Mongodb
Nats-Streaming
Osv-Scanner
Packer
Percona-Server-Mongodb-Operator
Podman
Prometheus-Mysqld-Exporter
Promxy-Fips
Rclone
Rootio-Golang.Org/X/Crypto
Sealed-Secrets
Skopeo
Snapd
Spice-Server
Spire-Server-Fips
Telegraf
Temporal
Terraform-Provider-Aws
Terraform-Provider-Azurerm
Terraform-Provider-External
Terraform-Provider-Google
Terraform-Provider-Helm
Terraform-Provider-Kubernetes
Terraform-Provider-Local
Terraform-Provider-Null
Terraform-Provider-Random
Terraform-Provider-Tls
Tigera-Operator
Trivy
Vault
Vault-K8S
Velero
Velociraptor
Weaviate
Weaviate-Fips