Bug 2533064 - CVE-2026-89090 rclone: Amazon AWS SDK for Go v2: Denial of Service via crafted event stream header [epel-all]
Summary: CVE-2026-89090 rclone: Amazon AWS SDK for Go v2: Denial of Service via crafte...
Keywords:
Status: NEW
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: rclone
Version: epel10
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Mikel Olasagasti Uranga
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["d4c099a3-adc9-4755-870c-f...
Depends On:
Blocks: CVE-2026-89090
TreeView+ depends on / blocked
 
Reported: 2026-09-14 14:08 UTC by Jon Weiser
Modified: 2026-09-14 14:08 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Jon Weiser 2026-09-14 14:08:51 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response frame containing a header value type outside the valid range.



To remediate this issue, users should upgrade to release-2026-03-23 or later, and patch any forked or derivative code.


Note You need to log in before you can comment on or make changes to this bug.