Bug 2533082

Summary: CVE-2026-89090 image-builder: Amazon AWS SDK for Go v2: Denial of Service via crafted event stream header [fedora-all]
Product: [Fedora] Fedora Reporter: Jon Weiser <jweiser>
Component: image-builderAssignee: Simon de Vlieger <cmdr>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: rawhideCC: cmdr, go-sig, osbuilders
Target Milestone: ---Keywords: Security, SecurityTracking
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: {"flaws": ["d4c099a3-adc9-4755-870c-f54adc031a1e"]}
Fixed In Version: Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2531982    

Description Jon Weiser 2026-09-14 14:11:02 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response frame containing a header value type outside the valid range.



To remediate this issue, users should upgrade to release-2026-03-23 or later, and patch any forked or derivative code.