PT-2026-84861 · Azure Linux+7 · Buildah+33

·

CVE-2026-78662

·

Published

2026-09-02

·

Updated

2026-09-09

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions The product name cannot be determined. (affected versions not specified)
Description A flaw exists where a channel registered in the mux's chanList remains unusable until it is established. A malicious peer can flood the incomingRequests of the channel, leading to a deadlock of the entire connection. This occurs because the system fails to properly handle packets before the channel reaches an established state.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-99126
AZL-99129
AZL-99144
AZL-99156
AZL-99165
AZL-99195
AZL-99207
AZL-99225
AZL-99249
AZL-99261
AZL-99273
AZL-99285
AZL-99312
AZL-99321
AZL-99384
CVE-2026-78662
GO-2026-6354
OPENSUSE-SU-2026:11727-1
OPENSUSE-SU-2026:21801-1
OPENSUSE-SU-2026:21812-1
OPENSUSE-SU-2026:21814-1
OPENSUSE-SU-2026:21816-1
OPENSUSE-SU-2026:21824-1

Affected Products

Buildah
Cert-Manager
Cf Cli
Containerized-Data-Importer-1.65
Cri-O
Crypto++
Docker Buildx
Docker Compose
Gh
Golang-1.17
Golang-1.20
Golang-1.21
Golang-1.22
Golang-1.23
Golang-1.24
Golang-1.25
Golang-1.26
Golang-Defaults
Golang-Go.Crypto
Golang.Org/X/Crypto
Golang.Org/X/Crypto/Ssh
Govulncheck-Vulndb
Hauler
Kubernetes
Kubevirt
Containers/Common
Moby-Engine
Nvidia Container Toolkit
Packer
Podman
Rclone
Telegraf
Trivy
Zk