Bug 2531002 (CVE-2026-87822)

Summary: CVE-2026-87822 t-digest: t-digest: Denial of Service via NaN centroid injection during deserialization
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: dfreiber, drow, gmalinko, janstey, jburrell, pdelbell, rstepani, vkumar
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in t-digest. A remote attacker can exploit a vulnerability in the `MergingDigest.fromBytes` deserialization process by injecting specially crafted "Not a Number" (NaN) values. These malicious values bypass validation checks, degrading sorting performance from efficient to significantly slower. This can lead to severe processing delays during merge operations, resulting in a Denial of Service (DoS) for the affected system.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2531221    
Bug Blocks:    

Description OSIDB Bzimport 2026-09-09 14:52:43 UTC
t-digest versions 3.1 through 3.3 fail to validate centroid means during deserialization in MergingDigest.fromBytes, allowing attackers to inject NaN values that bypass validation checks. Attackers can craft malicious serialized digests containing NaN centroids that degrade sorting performance from O(n log n) to O(n squared), causing severe processing delays during merge operations.