PT-2026-96849 · Netdata+1 · Netdata+1
CVE-2026-83603
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Netdata versions prior to 2.10.4
Description
The setuid-root
ndsudo helper command fail2ban-client-status-socket in src/collectors/utils/ndsudo.c accepts a caller-controlled --socket path from the low-privileged netdata service account. An attacker can direct the root fail2ban-client to a malicious UNIX socket. Subsequently, the CSocket.receive() function in fail2ban/client/csocket.py passes the returned data to pickle.loads(), which allows for the execution of attacker-controlled code as root on systems where fail2ban-client is installed. Pickle is a Python module used for serializing and deserializing Python object structures.Recommendations
Update to version 2.10.4 or nightly build 2.10.0-782-nightly.
Exploit
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netdata
Fail2Ban-Client