Bug 2533088 - CVE-2026-89090 docker-buildkit: Amazon AWS SDK for Go v2: Denial of Service via crafted event stream header [fedora-all]
Summary: CVE-2026-89090 docker-buildkit: Amazon AWS SDK for Go v2: Denial of Service v...
Keywords:
Status: NEW
Alias: None
Product: Fedora
Classification: Fedora
Component: docker-buildkit
Version: rawhide
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Brad Smith
QA Contact:
URL:
Whiteboard: {"flaws": ["d4c099a3-adc9-4755-870c-f...
Depends On:
Blocks: CVE-2026-89090
TreeView+ depends on / blocked
 
Reported: 2026-09-14 14:11 UTC by Jon Weiser
Modified: 2026-09-14 14:11 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Jon Weiser 2026-09-14 14:11:57 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response frame containing a header value type outside the valid range.



To remediate this issue, users should upgrade to release-2026-03-23 or later, and patch any forked or derivative code.


Note You need to log in before you can comment on or make changes to this bug.