Bug 2536500 (CVE-2026-44236) - CVE-2026-44236 rabbitmq-c: rabbitmq-c: Heap buffer overflow leading to denial of service
Summary: CVE-2026-44236 rabbitmq-c: rabbitmq-c: Heap buffer overflow leading to denial...
Keywords:
Status: NEW
Alias: CVE-2026-44236
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2537855
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-17 18:14 UTC by OSIDB Bzimport
Modified: 2026-10-05 03:30 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:75582 0 None None None 2026-10-05 03:30:40 UTC

Description OSIDB Bzimport 2026-09-17 18:14:17 UTC
rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersized connection.tune.frame_max value during amqp_login(), and rabbitmq-c accepts the value in amqp_login_inner() in librabbitmq/amqp_socket.c. amqp_tune_connection() in librabbitmq/amqp_connection.c uses frame_max to reallocate the outbound buffer without enforcing AMQP_FRAME_MIN_SIZE. Immediate serialization of connection.tune-ok through amqp_frame_to_bytes() writes beyond the undersized heap allocation, causing memory corruption and likely denial of service. An on-path attacker can also trigger the flaw against plaintext AMQP traffic. Code execution is theoretically possible but was not demonstrated. This issue is fixed in version 0.16.0.

Comment 2 Jon Orris 2026-10-05 03:30:39 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:75582 https://access.redhat.com/errata/RHSA-2026:75582


Note You need to log in before you can comment on or make changes to this bug.