Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-46603

Опубликовано: 14 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion.

A flaw was found in golang.org/x/image/vp8l. A remote attacker can cause a denial of service by providing a specially crafted VP8L image. This image, containing many unused Huffman tree groups, leads to excessive memory allocation during VP8L decoding, resulting in memory exhaustion.

Отчет

This is an Important severity flaw due to the potential for a remote attacker to trigger a denial of service. By providing a specially crafted VP8L image, an attacker can exploit a vulnerability in golang.org/x/image/vp8l that causes excessive memory allocation, leading to memory exhaustion in applications processing these images. This could impact the availability of services utilizing the affected component.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4cryostat/cryostat-storage-rhel9Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/volsync-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2516086golang.org/x/image/vp8l: golang.org/x/image/vp8l: Denial of Service via excessive memory allocation

EPSS

Процентиль: 35%
0.00417
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
25 дней назад

VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion.

CVSS3: 7.5
nvd
25 дней назад

VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion.

CVSS3: 7.5
debian
25 дней назад

VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amo ...

EPSS

Процентиль: 35%
0.00417
Низкий

7.5 High

CVSS3

Уязвимость CVE-2026-46603