Bug 2548048 (CVE-2026-61801) - CVE-2026-61801 github.com/moby/sys/user: moby/sys/user: Denial of Service via crafted user or group database files
Summary: CVE-2026-61801 github.com/moby/sys/user: moby/sys/user: Denial of Service via...
Keywords:
Status: NEW
Alias: CVE-2026-61801
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2548481 2548482 2548483 2548484 2548485 2548486 2548487 2548488 2548492 2548493 2548494 2548495 2548496 2548497 2548498 2548499 2548500 2548502 2548503 2548505 2548506 2548507 2548508 2548515 2548516 2548517 2548518 2548519 2548520 2548521 2548522 2548523 2548524 2548525 2548526 2548527 2548528 2548529 2548530 2548531 2548532 2548533 2548534 2548535 2548536 2548537 2548539 2548491 2548514
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-10-08 16:41 UTC by OSIDB Bzimport
Modified: 2026-10-09 12:22 UTC (History)
141 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-10-08 16:41:48 UTC
The `github.com/moby/sys/user` package provides Go utilities for parsing and looking up entries in Unix-style user and group database files. Versions before 0.4.1 do not sufficiently limit entries when parsing `/etc/passwd`- or `/etc/group`-style files, allowing an attacker who can supply a specially crafted file to cause excessive memory consumption and potentially terminate the affected process due to an out-of-memory condition. This issue is patched in version 0.4.1. As a workaround, avoid parsing attacker-controlled user or group database files, or validate and limit untrusted input before parsing it.


Note You need to log in before you can comment on or make changes to this bug.