PT-2026-96846 · Netdata · Netdata
CVE-2026-83600
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Netdata versions prior to 2.10.4
Description
An authenticated child agent can send an oversized CHART SLOT value that is processed by the
str2ull encoded function and passed to pluginsd rrdset cache put to slot in src/plugins.d/pluginsd internals.h. This causes reallocz to request a chart-pointer array of approximately 16 GiB. The resulting allocation failure triggers a fatal error that aborts the parent Netdata agent, leading to the repeated disabling of centralized monitoring while stream access remains active.Recommendations
Update to version 2.10.4 or nightly build 2.10.0-782-nightly.
Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netdata