AZL-105534

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105534.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-105534
Upstream
Published
2026-09-29T15:17:27Z
Modified
2026-10-03T14:16:34Z
Summary
CVE-2026-63209 affecting package keda 2.14.1-19
Details

compress provides various compression algorithms. Prior to version 1.18.7, a signed integer overflow vulnerability in s2.NewDict() allows an attacker to bypass repeat index validation by supplying a dictionary with a uvarint-encoded repeat value exceeding MaxInt64. When Dict.Encode() is subsequently called, the overflowed negative repeat value causes an out-of-bounds memory access via unsafe.Pointer arithmetic, crashing the process with SIGSEGV. This issue has been patched in version 1.18.7.

References

Affected packages

Azure Linux:3 / keda

Package

Name
keda
Purl
pkg:rpm/azure-linux/keda

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
2.14.1-19

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105534.json"