PT-2026-62048 · Alpaquita+11 · Buildah+39
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
The product name cannot be determined (affected versions not specified)
Description
Parsing an invalid SVCB (Service Binding) or HTTPS RR (Resource Record) can cause a panic when the size of a parameter value overflows the message buffer.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Buildah
Calicoctl
Cilium-Cli
Kubernetes Containerd
Cortex
Cri-Tools
Docker-Cli-Buildx
Dynatrace-Operator
Etcd
External Secrets Operator
Go
Golang
Golang-1.23
Golang-Golang-X-Net
Golang.Org/X/Net
Golang.Org/X/Net/Dns/Dnsmessage
Govulncheck-Vulndb
Grype
Ingress-Nginx-Controller-1.13
Ingress-Nginx-Controller-1.14
Ingress-Nginx-Controller-1.15
Knative Serving
Kube-Vip
Kubevirt
Kubevirt-1.6
Kubevirt-1.8
Mongodb
Net
Osv-Scanner
Podman
Prometheus
Rclone
Rootio-Golang.Org/X/Net
Rootlesskit
Runc
Sealed-Secrets
Stakater-Reloader
Stdlib
Trust-Manager
Wave