Bug 2498527 (CVE-2026-60108) - CVE-2026-60108 zeek: Zeek: Denial of Service via uncontrolled memory consumption in FTP analyzer
Summary: CVE-2026-60108 zeek: Zeek: Denial of Service via uncontrolled memory consumpt...
Keywords:
Status: NEW
Alias: CVE-2026-60108
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2499664 2499665
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-09 15:01 UTC by OSIDB Bzimport
Modified: 2026-07-13 13:17 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-09 15:01:33 UTC
Zeek before 8.0.9 contains an uncontrolled memory consumption vulnerability in the FTP analyzer that allows unauthenticated remote attackers to cause process termination by sending a crafted FTP control session negotiating AUTH GSSAPI followed by a large ADAT control line. Attackers can exploit the NVT_Analyzer component's lack of a maximum line length check, causing it to continuously double its internal buffer without bounds during base64 decoding of an attacker-controlled ADAT token, resulting in denial of service of the Zeek sensor.


Note You need to log in before you can comment on or make changes to this bug.