PT-2026-96847 · Netdata · Netdata
CVE-2026-83601
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Netdata versions prior to 2.10.4
Description
An authenticated child agent can send an oversized DIMENSION SLOT value that is processed by the
str2ull encoded function and passed to pluginsd rrddim put to slot in src/plugins.d/pluginsd internals.h without an upper bound. This allows prd array create in src/database/rrdset-pluginsd-array.h to wrap the size t allocation calculation while keeping the original large array size. Consequently, the initialization loop writes beyond the undersized heap allocation, leading to a crash of the parent agent.Recommendations
Update to version 2.10.4 or nightly build 2.10.0-782-nightly.
Exploit
Fix
Memory Corruption
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netdata