<Vulnerability name="CVE-2026-46385">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-05-29T19:58:59</PublicDate>
    <Bugzilla id="2483475" url="https://bugzilla.redhat.com/show_bug.cgi?id=2483475" xml:lang="en:us">
github.com/hamba/avro/v2: github.com/linkedin/goavro/v2: CPU Exhaustion in Avro Decoder via Unbounded Block-Count Iteration
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>7.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-835</CWE>
    <Details xml:lang="en:us" source="Mitre">
iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, the Avro array and map decoders looped over an attacker-controlled block-count value without checking the underlying reader's error state inside the loop body. Reader.ReadBlockHeader returns the count as a Go int, which is 64-bit on amd64 / arm64 targets — so a producer can declare a block of up to math.MaxInt64 (~9.2 × 10¹⁸) elements followed by EOF (or any truncated payload), and the decoder will attempt that many no-op iterations before propagating the error. The realistic ceiling is "indefinite until the worker is killed externally" — a single hostile payload pins a CPU core until the process is OOM-killed, deadline-cancelled, or terminated. Remote, unauthenticated denial-of-service. This vulnerability is fixed in 2.33.0.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in the Avro array and map decoding logic in Go Avro. The decoder failed to properly stop processing after encountering read errors while iterating over attacker-controlled block-count values, leading to excessive resource consumption. A remote unauthenticated attacker could exploit this issue using specially crafted Avro payloads causing denial of service, where the affected system's CPU is consumed indefinitely until the process is terminated.
    </Details>
    <Statement xml:lang="en:us">
This vulnerability affects Avro array and map decoding functionality in affected Go Avro libraries. Red Hat Product Security has assessed this issue as an Important severity vulnerability.

A remote unauthenticated attacker may supply specially crafted Avro payloads containing excessively large block-count values followed by truncated or invalid data. Because the decoder continued iterating after the underlying reader entered an error state, affected applications may consume excessive CPU resources for extended periods of time, potentially leading to denial of service.

The currently available analysis demonstrates CPU exhaustion and service disruption but does not demonstrate confidentiality or integrity impact. Therefore, Red Hat assessed the impact as limited to Availability (A:H).
    </Statement>
    <Mitigation xml:lang="en:us">
Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available.
    </Mitigation>
    <AffectedRelease cpe="cpe:/a:redhat:cryostat:4::el9">
        <ProductName>Cryostat 4 on RHEL 9</ProductName>
        <ReleaseDate>2026-07-29T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:48151">RHSA-2026:48151</Advisory>
        <Package name="cryostat/cryostat-storage-rhel9">cryostat/cryostat-storage-rhel9:4.2.0-19</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:multicluster_globalhub:1.4::el9">
        <ProductName>Multicluster Global Hub 1.4.5</ProductName>
        <ReleaseDate>2026-07-16T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:41030">RHSA-2026:41030</Advisory>
        <Package name="multicluster-globalhub/multicluster-globalhub-grafana-rhel9">multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1784060681</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:multicluster_globalhub:1.6::el9">
        <ProductName>Multicluster Global Hub 1.6.5</ProductName>
        <ReleaseDate>2026-07-23T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:44622">RHSA-2026:44622</Advisory>
        <Package name="multicluster-globalhub/multicluster-globalhub-grafana-rhel9">multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1784561376</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:multicluster_globalhub:1.7::el9">
        <ProductName>Multicluster Global Hub 1.7.0</ProductName>
        <ReleaseDate>2026-07-28T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:47149">RHSA-2026:47149</Advisory>
        <Package name="multicluster-globalhub/multicluster-globalhub-grafana-rhel9">multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1784906628</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:multicluster_globalhub:1.7::el9">
        <ProductName>Multicluster Global Hub 1.7.0</ProductName>
        <ReleaseDate>2026-08-11T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:53530">RHSA-2026:53530</Advisory>
        <Package name="multicluster-globalhub/multicluster-globalhub-grafana-rhel9">multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1785442872</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:acm:2.11::el9">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2.11</ProductName>
        <ReleaseDate>2026-07-16T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:41064">RHSA-2026:41064</Advisory>
        <Package name="rhacm2/acm-grafana-rhel9">rhacm2/acm-grafana-rhel9:1783578847</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:acm:2.13::el9">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2.13</ProductName>
        <ReleaseDate>2026-06-28T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:30651">RHSA-2026:30651</Advisory>
        <Package name="rhacm2/acm-grafana-rhel9">rhacm2/acm-grafana-rhel9:1782383730</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:acm:2.16::el9">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2.16</ProductName>
        <ReleaseDate>2026-08-19T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:57191">RHSA-2026:57191</Advisory>
        <Package name="rhacm2/acm-grafana-rhel9">rhacm2/acm-grafana-rhel9:1786908968</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:acm:2.17::el9">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2.17</ProductName>
        <ReleaseDate>2026-08-26T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:60386">RHSA-2026:60386</Advisory>
        <Package name="rhacm2/acm-grafana-rhel9">rhacm2/acm-grafana-rhel9:1787316467</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:multicluster_globalhub:1.5::el9">
        <ProductName>Red Hat multicluster global hub 1.5.3</ProductName>
        <ReleaseDate>2026-07-21T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:42852">RHSA-2026:42852</Advisory>
        <Package name="multicluster-globalhub/multicluster-globalhub-grafana-rhel9">multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1784562060</Package>
    </AffectedRelease>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:10">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>grafana</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>grafana</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>grafana</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <FixState>Affected</FixState>
        <PackageName>opentelemetry-collector-contrib</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-46385
https://nvd.nist.gov/vuln/detail/CVE-2026-46385
https://github.com/iskorotkov/avro/security/advisories/GHSA-w8j3-pq8g-8m7w
    </References>
</Vulnerability>