CVE-2026-43970

Description

A flaw was found in cowlib. This vulnerability, categorized as Improper Handling of Highly Compressed Data (Data Amplification), allows an unauthenticated remote attacker to cause a denial of service (DoS). By sending a specially crafted SPDY frame, the cow_spdy:inflate/2 function in cowlib passes highly compressed data to zlib:inflate/2 without proper size bounds. This can lead to excessive memory consumption, causing the affected system to run out of memory and crash.

Statement

Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.

Understanding the Weakness (CWE)

Availability

Technical Impact: DoS: Amplification; DoS: Crash, Exit, or Restart; DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory)

System resources, CPU and memory, can be quickly consumed. This can lead to poor system performance or system crash.

Frequently Asked Questions

Want to get errata notifications? Sign up here.