Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-24825

Опубликовано: 27 янв. 2026
Источник: redhat
CVSS3: 5.3

Описание

Missing Release of Memory after Effective Lifetime vulnerability in ydb-platform ydb (contrib/libs/yajl modules). This vulnerability is associated with program files yail_tree.C. This issue affects ydb: through 24.4.4.2.

A flaw was found in ydb. This memory management vulnerability, identified as a 'Missing Release of Memory after Effective Lifetime', exists within the contrib/libs/yajl modules, specifically affecting the yail_tree.C program file. A remote attacker could exploit this by repeatedly triggering memory allocations without proper deallocation. This could lead to resource exhaustion, ultimately causing a Denial of Service (DoS) for the affected system.

Отчет

This MODERATE impact memory leak in the yajl modules of ydb can lead to a Denial of Service. A remote attacker could exploit this vulnerability by repeatedly triggering memory allocations without proper deallocation, causing resource exhaustion..

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/cluster-logging-operator-bundleUnder investigation
Logging Subsystem for Red Hat OpenShiftopenshift-logging/cluster-logging-rhel9-operatorUnder investigation
Logging Subsystem for Red Hat OpenShiftopenshift-logging/eventrouter-rhel9Under investigation
Logging Subsystem for Red Hat OpenShiftopenshift-logging/fluentd-rhel8Under investigation
Logging Subsystem for Red Hat OpenShiftopenshift-logging/fluentd-rhel9Under investigation
Logging Subsystem for Red Hat OpenShiftopenshift-logging/log-file-metric-exporter-rhel9Under investigation
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-view-plugin-rhel9Under investigation
Logging Subsystem for Red Hat OpenShiftopenshift-logging/vector-rhel9Under investigation
Red Hat 3scale API Management Platform 23scale-amp20/backendUnder investigation
Red Hat 3scale API Management Platform 23scale-amp21/backendUnder investigation

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-401
https://bugzilla.redhat.com/show_bug.cgi?id=2433231ydb: ydb: Denial of Service via memory leak

5.3 Medium

CVSS3

Связанные уязвимости

nvd
2 месяца назад

Missing Release of Memory after Effective Lifetime vulnerability in ydb-platform ydb (contrib/libs/yajl modules). This vulnerability is associated with program files yail_tree.C. This issue affects ydb: through 24.4.4.2.

github
2 месяца назад

Missing Release of Memory after Effective Lifetime vulnerability in ydb-platform ydb (contrib/libs/yajl modules). This vulnerability is associated with program files yail_tree.C. This issue affects ydb: through 24.4.4.2.

5.3 Medium

CVSS3