Bug 2542409 - CVE-2026-84971 netdata: MONGOCRYPT: Denial of Service via improper handling of encrypted data [epel-all]
Summary: CVE-2026-84971 netdata: MONGOCRYPT: Denial of Service via improper handling o...
Keywords:
Status: NEW
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: netdata
Version: epel10
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Orphan Owner
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["1af34c24-ec55-43f0-859d-8...
Depends On:
Blocks: CVE-2026-84971
TreeView+ depends on / blocked
 
Reported: 2026-09-28 10:44 UTC by nlevinki
Modified: 2026-09-28 10:44 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description nlevinki 2026-09-28 10:44:12 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Improper handling of an unexpected value size in the decryption path of a client-side encryption library can cause a failed internal check that terminates the process using the library. A party able to place a suitably formed encrypted value where an application will decrypt it, or able to control the responses the application receives, may cause that application to stop running.


Note You need to log in before you can comment on or make changes to this bug.