Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-24825

Опубликовано: 27 янв. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Missing Release of Memory after Effective Lifetime vulnerability in ydb-platform ydb (contrib/libs/yajl modules). This vulnerability is associated with program files yail_tree.C. This issue affects ydb: through 24.4.4.2.

A flaw was found in ydb. This memory management vulnerability, identified as a 'Missing Release of Memory after Effective Lifetime', exists within the contrib/libs/yajl modules, specifically affecting the yail_tree.C program file. A remote attacker could exploit this by repeatedly triggering memory allocations without proper deallocation. This could lead to resource exhaustion, ultimately causing a Denial of Service (DoS) for the affected system.

Отчет

This MODERATE impact memory leak in the yajl modules of ydb can lead to a Denial of Service. A remote attacker could exploit this vulnerability by repeatedly triggering memory allocations without proper deallocation, causing resource exhaustion..

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/cluster-logging-operator-bundleFix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/cluster-logging-rhel9-operatorFix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/eventrouter-rhel9Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/fluentd-rhel8Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/fluentd-rhel9Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/log-file-metric-exporter-rhel9Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-view-plugin-rhel9Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/vector-rhel9Fix deferred
Red Hat 3scale API Management Platform 23scale-amp20/backendFix deferred
Red Hat 3scale API Management Platform 23scale-amp21/backendFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-401
https://bugzilla.redhat.com/show_bug.cgi?id=2433231ydb: ydb: Denial of Service via memory leak

EPSS

Процентиль: 24%
0.00312
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

nvd
7 месяцев назад

Missing Release of Memory after Effective Lifetime vulnerability in ydb-platform ydb (contrib/libs/yajl modules). This vulnerability is associated with program files yail_tree.C. This issue affects ydb: through 24.4.4.2.

github
7 месяцев назад

Missing Release of Memory after Effective Lifetime vulnerability in ydb-platform ydb (contrib/libs/yajl modules). This vulnerability is associated with program files yail_tree.C. This issue affects ydb: through 24.4.4.2.

EPSS

Процентиль: 24%
0.00312
Низкий

5.3 Medium

CVSS3

Уязвимость CVE-2026-24825