GHSA-mjcv-p78q-w5fw

Suggest an improvement
Source
https://github.com/advisories/GHSA-mjcv-p78q-w5fw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-mjcv-p78q-w5fw/GHSA-mjcv-p78q-w5fw.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-mjcv-p78q-w5fw
Aliases
  • CVE-2026-61801
Published
2026-10-08T16:08:33Z
Modified
2026-10-08T16:15:05Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
github.com/moby/sys/user has a possible DoS via unbounded parsing of user and group database files
Details

A denial-of-service (DoS) vulnerability exists in github.com/moby/sys/user before v0.4.1 when parsing specially crafted user or group database files. An attacker able to supply a malicious /etc/passwd or /etc/group-style file may cause excessive memory consumption, potentially resulting in process termination due to Out Of Memory (OOM) conditions.

This issue is related to containerd [CVE-2026-47262] / GHSA-jpcc-p29g-p8mq, which describes one practical exploitation path through processing untrusted container image content. Applications using github.com/moby/sys/user to parse untrusted user or group database files may be similarly affected.

Impact

github.com/moby/sys/user versions before v0.4.1 do not place sufficient limits on entries while parsing user and group database files. A specially crafted file may cause excessive memory consumption, potentially leading to process termination due to Out Of Memory (OOM) conditions.

Applications that use github.com/moby/sys/user to parse user-supplied or otherwise untrusted /etc/passwd or /etc/group files may be affected. The severity depends on whether an attacker can influence the contents of files being parsed.

Patches

This issue is fixed in github.com/moby/sys/user v0.4.1. Users should upgrade to v0.4.1 or later.

Workarounds

Avoid parsing attacker-controlled /etc/passwd or /etc/group-style files with affected versions of github.com/moby/sys/user.

Applications that must process untrusted user or group database files should validate and limit accepted input before parsing. Upgrading to v0.4.1 or later is the recommended remediation.

References

Database specific
{
    "cwe_ids": [
        "CWE-400"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-08T16:08:33Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
}
References

Affected packages

Go / github.com/moby/sys/user

Package

Name
github.com/moby/sys/user
View open source insights on deps.dev
Purl
pkg:golang/github.com/moby/sys/user

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.4.1

Database specific

last_known_affected_version_range
"<= 0.4.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-mjcv-p78q-w5fw/GHSA-mjcv-p78q-w5fw.json"