CVE-2026-85201
6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L
Summary
In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-delimited protobuf message received through the Control Interface FIFO. A workload granted Control Interface access can specify an excessive message length, causing an unbounded memory allocation that may abort the Ankaios agent process. This results in loss of orchestration services for workloads managed by the affected agent.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Eclipse Foundation | Eclipse Ankaios | 0.1.0 <= 1.0.1 | affected |
Weaknesses
- CWE-789: CWE-789 Memory allocation with excessive size value
- CWE-1284: CWE-1284 Improper validation of specified quantity in input
References
- https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/900
- https://github.com/eclipse-ankaios/ankaios/releases/tag/v1.0.2
- https://github.com/eclipse-ankaios/ankaios/pull/791
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.