Description
A flaw was found in claircore's apk package scanner. Malformed package-database data in a container layer can cause an out-of-bounds access that panics the scanner. If that panic is not recovered, the Clair indexer process can crash, leading to a denial of service.
Published: 2026-07-20
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw lies in claircore's apk package scanner, where malformed package‑database data in a container layer can trigger an out‑of‑bounds read. This out‑of‑bounds access causes a panic that, if not recovered, crashes the Clair indexer process. The result is a denial of service that interrupts vulnerability scanning for clouds or clusters managed by Red Hat Advanced Cluster Security or Quay. The weakness is a classic example of CWE‑125, a buffer under-read that leads to program instability.

Affected Systems

The vulnerability affects Red Hat Advanced Cluster Security 4 and Red Hat Quay 3. No specific sub‑version ranges are listed, so all instances of these product versions are potentially impacted.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, and the EPSS score of <1% indicates a low likelihood of exploitation. Based on the description, it is inferred that an attacker could supply a container image with crafted package‑database data— for example by pushing a malicious image to a registry or tampering with a layer on a trusted registry— to trigger the out‑of‑bounds read. If the panic is not recovered, the Clair indexer process crashes, causing a temporary loss of scanning capability. The flaw is not listed in the CISA KEV catalog, and no patch is currently available, so mitigations must rely on limiting indexing traffic and isolating failures.

Generated by OpenCVE AI on July 30, 2026 at 19:44 UTC.

Remediation

Vendor Workaround

Limit image push/indexing to trusted sources until a fix is available. Where possible, run indexing so a single scanner failure cannot disrupt shared indexing capacity.


OpenCVE Recommended Actions

  • Limit image push and indexing to trusted sources until an official fix is released. Where possible, run indexing so that a single scanner failure cannot disrupt shared indexing capacity.
  • Run the Clair indexer in isolated worker containers, ensuring that a crash of the indexer does not shut down the entire scanning service for shared indexing capacity.
  • Monitor Clair indexer logs for panic events and restart the service promptly when a crash is detected.

Generated by OpenCVE AI on July 30, 2026 at 19:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat quay 3
Vendors & Products Redhat quay 3

Mon, 20 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 20 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in claircore's apk package scanner. Malformed package-database data in a container layer can cause an out-of-bounds access that panics the scanner. If that panic is not recovered, the Clair indexer process can crash, leading to a denial of service.
Title Claircore: claircore: denial of service via out-of-bounds slice in claircore's apk installed-database parser
First Time appeared Redhat
Redhat advanced Cluster Security
Redhat quay
Weaknesses CWE-125
CPEs cpe:/a:redhat:advanced_cluster_security:4
cpe:/a:redhat:quay:3
Vendors & Products Redhat
Redhat advanced Cluster Security
Redhat quay
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Redhat Advanced Cluster Security Quay Quay 3
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-07-20T13:03:28.164Z

Reserved: 2026-07-20T08:01:11.264Z

Link: CVE-2026-16254

cve-icon Vulnrichment

Updated: 2026-07-20T13:03:24.228Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-20T07:58:00Z

Links: CVE-2026-16254 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:35:50Z

Weaknesses