UBUNTU-CVE-2026-49017

Source
https://ubuntu.com/security/CVE-2026-49017
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-49017.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-49017
Upstream
  • CVE-2026-49017
Published
2026-05-27T02:16:00Z
Modified
2026-06-09T21:17:22.938999500Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty buffer and re-reads, causing the proxy-server worker handling the request to become permanently unresponsive with increasing CPU and memory consumption. An authenticated attacker can systematically exhaust all proxy-server workers, resulting in denial of service. The defect was introduced in Swift 2.36.0.

References

Affected packages

Ubuntu:25.10 / swift

Package

Name
swift
Purl
pkg:deb/ubuntu/swift?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.35.0-0ubuntu1
2.35.0+git2025070714.1428eb3b5-0ubuntu1
2.36.0-0ubuntu1
2.36.0-0ubuntu1.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "python3-swift",
            "binary_version": "2.36.0-0ubuntu1.1"
        },
        {
            "binary_name": "swift",
            "binary_version": "2.36.0-0ubuntu1.1"
        },
        {
            "binary_name": "swift-account",
            "binary_version": "2.36.0-0ubuntu1.1"
        },
        {
            "binary_name": "swift-container",
            "binary_version": "2.36.0-0ubuntu1.1"
        },
        {
            "binary_name": "swift-object",
            "binary_version": "2.36.0-0ubuntu1.1"
        },
        {
            "binary_name": "swift-object-expirer",
            "binary_version": "2.36.0-0ubuntu1.1"
        },
        {
            "binary_name": "swift-proxy",
            "binary_version": "2.36.0-0ubuntu1.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-49017.json"

Ubuntu:26.04:LTS / swift

Package

Name
swift
Purl
pkg:deb/ubuntu/swift?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.36.0-0ubuntu1
2.37.0-0ubuntu1
2.37.1-0ubuntu2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "python3-swift",
            "binary_version": "2.37.1-0ubuntu2"
        },
        {
            "binary_name": "swift",
            "binary_version": "2.37.1-0ubuntu2"
        },
        {
            "binary_name": "swift-account",
            "binary_version": "2.37.1-0ubuntu2"
        },
        {
            "binary_name": "swift-container",
            "binary_version": "2.37.1-0ubuntu2"
        },
        {
            "binary_name": "swift-object",
            "binary_version": "2.37.1-0ubuntu2"
        },
        {
            "binary_name": "swift-object-expirer",
            "binary_version": "2.37.1-0ubuntu2"
        },
        {
            "binary_name": "swift-proxy",
            "binary_version": "2.37.1-0ubuntu2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-49017.json"