Описание
A flaw was found in claircore's RPM package scanner. Crafted RPM header data in a container layer can cause an unchecked type assertion to panic the scanner. The panic is not recovered, causing the Clair indexer process to crash, leading to a denial of service.
Отчет
Red Hat Quay Clair and RHACS Scanner V4 deployments run the indexer as multiple OpenShift pods (default replica count >= 2) with automatic kubelet restart on crash. An unrecovered panic in claircore RPM header parsing terminates one indexer pod; the remaining replicas and automatic pod restart limit the impact to a temporary interruption of image indexing rather than a lasting registry or scanning outage. Availability impact is therefore Low (A:L), consistent with the precedent claircore panic-DoS flaw CVE-2026-16254 (apk parser out-of-bounds slice), which received the same CVSS vector and score.
Меры по смягчению последствий
Where possible, configure the indexer to run scanner workloads in isolated processes or containers so that a single scanner panic cannot terminate the shared indexer. Alternatively, deploy multiple indexer replicas behind a load balancer to reduce the blast radius of a single-process crash.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Advanced Cluster Security 4 | advanced-cluster-security/rhacs-main-rhel8 | Fix deferred | ||
| Red Hat Advanced Cluster Security 4 | advanced-cluster-security/rhacs-main-rhel9 | Fix deferred | ||
| Red Hat Advanced Cluster Security 4 | advanced-cluster-security/rhacs-operator-bundle | Fix deferred | ||
| Red Hat Advanced Cluster Security 4 | advanced-cluster-security/rhacs-rhel8-operator | Fix deferred | ||
| Red Hat Advanced Cluster Security 4 | advanced-cluster-security/rhacs-rhel9-operator | Fix deferred | ||
| Red Hat Advanced Cluster Security 4 | advanced-cluster-security/rhacs-roxctl-rhel8 | Fix deferred | ||
| Red Hat Advanced Cluster Security 4 | advanced-cluster-security/rhacs-roxctl-rhel9 | Fix deferred | ||
| Red Hat Advanced Cluster Security 4 | advanced-cluster-security/rhacs-scanner-v4-rhel8 | Fix deferred | ||
| Red Hat Advanced Cluster Security 4 | advanced-cluster-security/rhacs-scanner-v4-rhel9 | Fix deferred | ||
| Red Hat Quay 3 | quay/clair-rhel8 | Fix deferred |
Показывать по
Дополнительная информация
Статус:
4.3 Medium
CVSS3
Связанные уязвимости
A flaw was found in claircore's RPM package scanner. Crafted RPM header data in a container layer can cause an unchecked type assertion to panic the scanner. The panic is not recovered, causing the Clair indexer process to crash, leading to a denial of service.
A flaw was found in claircore's RPM package scanner. Crafted RPM header data in a container layer can cause an unchecked type assertion to panic the scanner. The panic is not recovered, causing the Clair indexer process to crash, leading to a denial of service.
4.3 Medium
CVSS3