Vulnerability GHSA-mjcv-p78q-w5fw

Medium Risk
MEDIUM RISK
CVSS Score: 5.5
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
7 hours ago
October 08, 2026 at 04:08 PM UTC
github.com/moby/sys/user has a possible DoS via unbounded parsing of user and group database files
v0.1.0 - v0.4.0
v0.1.0 - v0.4.0

Summary

github.com/moby/sys/user has a possible DoS via unbounded parsing of user and group database files

Details

A denial-of-service (DoS) vulnerability exists in github.com/moby/sys/user before v0.4.1 when parsing specially crafted user or group database files. An attacker able to supply a malicious /etc/passwd or /etc/group-style file may cause excessive memory consumption, potentially resulting in process termination due to Out Of Memory (OOM) conditions.

This issue is related to containerd [CVE-2026-47262] / GHSA-jpcc-p29g-p8mq, which describes one practical exploitation path through processing untrusted container image content. Applications using github.com/moby/sys/user to parse untrusted user or group database files may be similarly affected.

Impact

github.com/moby/sys/user versions before v0.4.1 do not place sufficient limits on entries while parsing user and group database files. A specially crafted file may cause excessive memory consumption, potentially leading to process termination due to Out Of Memory (OOM) conditions.

Applications that use github.com/moby/sys/user to parse user-supplied or otherwise untrusted /etc/passwd or /etc/group files may be affected. The severity depends on whether an attacker can influence the contents of files being parsed.

Patches

This issue is fixed in github.com/moby/sys/user v0.4.1. Users should upgrade to v0.4.1 or later.

Workarounds

Avoid parsing attacker-controlled /etc/passwd or /etc/group-style files with affected versions of github.com/moby/sys/user.

Applications that must process untrusted user or group database files should validate and limit accepted input before parsing. Upgrading to v0.4.1 or later is the recommended remediation.

References

Impacted packages

Timeline

Published
7 hours ago
October 08, 2026 at 04:08 PM UTC
Last Modified
6 hours ago
October 08, 2026 at 04:15 PM UTC