Impact
A flaw in claircore's RPM package scanner allows crafted RPM header data in a container layer to trigger an unchecked type assertion, causing the scanner to panic. The panic is not recovered, crashing the Clair indexer process and resulting in a denial of service. The weakness is identified as CWE-617.
Affected Systems
The vulnerability affects Red Hat Advanced Cluster Security 4 and Red Hat Quay 3. No specific patch versions are listed in the current data; the products as a whole are impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, suggesting limited publicly known exploitation activity. Based on the description, the attack likely requires an attacker to supply a malicious container image containing malformed RPM header data; this could be achieved through uploading a container image to a registry that is subsequently scanned by the affected services.
OpenCVE Enrichment