PT-2026-96847 · Netdata · Netdata

CVE-2026-83601

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Netdata versions prior to 2.10.4
Description An authenticated child agent can send an oversized DIMENSION SLOT value that is processed by the str2ull encoded function and passed to pluginsd rrddim put to slot in src/plugins.d/pluginsd internals.h without an upper bound. This allows prd array create in src/database/rrdset-pluginsd-array.h to wrap the size t allocation calculation while keeping the original large array size. Consequently, the initialization loop writes beyond the undersized heap allocation, leading to a crash of the parent agent.
Recommendations Update to version 2.10.4 or nightly build 2.10.0-782-nightly.

Exploit

Fix

Memory Corruption

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-83601
GHSA-3QH4-842W-FVRM

Affected Products

Netdata