Bug 2502701 (CVE-2026-16254) - CVE-2026-16254 claircore: claircore: Denial of service via out-of-bounds slice in claircore's apk installed-database parser
Summary: CVE-2026-16254 claircore: claircore: Denial of service via out-of-bounds slic...
Keywords:
Status: NEW
Alias: CVE-2026-16254
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-20 07:59 UTC by OSIDB Bzimport
Modified: 2026-07-20 08:13 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-20 07:59:17 UTC
A denial-of-service issue was reported in claircore (used by Clair, including with Quay). When indexing certain container image layers, the apk package scanner can panic on malformed package-database content. That panic is not handled on the indexing path, so it can terminate the indexer process. An attacker who can get a crafted image layer indexed may trigger this condition.

Comment 1 Yadnyawalk Tale 2026-07-20 08:09:35 UTC
CVSS Justification:

A:H -> A:L 

A:H fits a long-lived single indexer process that dies for everyone until manually recovered.
A:L fits typical Quay/Clair on OpenShift/k8s: pod dies, kubelet restarts it, impact is a short indexing blip / log noise, not lasting outage - unless someone can crash-loop it continuously (still usually scored A:L when recovery is automatic).


Note You need to log in before you can comment on or make changes to this bug.