AZL-105906

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105906.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-105906
Upstream
Published
2026-09-29T15:17:27Z
Modified
2026-10-03T14:16:40Z
Summary
CVE-2026-63209 affecting package telegraf 1.31.0-33
Details

compress provides various compression algorithms. Prior to version 1.18.7, a signed integer overflow vulnerability in s2.NewDict() allows an attacker to bypass repeat index validation by supplying a dictionary with a uvarint-encoded repeat value exceeding MaxInt64. When Dict.Encode() is subsequently called, the overflowed negative repeat value causes an out-of-bounds memory access via unsafe.Pointer arithmetic, crashing the process with SIGSEGV. This issue has been patched in version 1.18.7.

References

Affected packages

Azure Linux:3 / telegraf

Package

Name
telegraf
Purl
pkg:rpm/azure-linux/telegraf

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.31.0-33

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105906.json"