Description
A flaw was found in claircore's RPM package scanner. Crafted RPM header data in a container layer can cause an unchecked type assertion to panic the scanner. The panic is not recovered, causing the Clair indexer process to crash, leading to a denial of service.
Published: 2026-08-11
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in claircore's RPM package scanner allows crafted RPM header data in a container layer to trigger an unchecked type assertion, causing the scanner to panic. The panic is not recovered, crashing the Clair indexer process and resulting in a denial of service. The weakness is identified as CWE-617.

Affected Systems

The vulnerability affects Red Hat Advanced Cluster Security 4 and Red Hat Quay 3. No specific patch versions are listed in the current data; the products as a whole are impacted.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, suggesting limited publicly known exploitation activity. Based on the description, the attack likely requires an attacker to supply a malicious container image containing malformed RPM header data; this could be achieved through uploading a container image to a registry that is subsequently scanned by the affected services.

Generated by OpenCVE AI on August 11, 2026 at 09:21 UTC.

Remediation

Vendor Workaround

Where possible, configure the indexer to run scanner workloads in isolated processes or containers so that a single scanner panic cannot terminate the shared indexer. Alternatively, deploy multiple indexer replicas behind a load balancer to reduce the blast radius of a single-process crash.


OpenCVE Recommended Actions

  • Configure the Clair indexer to run scanner workloads in isolated processes or containers so that a single scanner panic cannot terminate the shared indexer.
  • Deploy multiple indexer replicas behind a load balancer to reduce the blast radius of a single‑process crash.
  • Ensure the claircore scanner component is updated to a version that fixes the unchecked type assertion; if no patch is available yet, consider upgrading Red Hat Advanced Cluster Security or Quay once patches are released and avoid using container images with potentially malicious RPM headers.

Generated by OpenCVE AI on August 11, 2026 at 09:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat quay 3
Vendors & Products Redhat quay 3

Tue, 11 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 11 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in claircore's RPM package scanner. Crafted RPM header data in a container layer can cause an unchecked type assertion to panic the scanner. The panic is not recovered, causing the Clair indexer process to crash, leading to a denial of service.
Title Claircore: claircore: denial of service via unchecked type assertion in rpm header parser
First Time appeared Redhat
Redhat advanced Cluster Security
Redhat quay
Weaknesses CWE-617
CPEs cpe:/a:redhat:advanced_cluster_security:4
cpe:/a:redhat:quay:3
Vendors & Products Redhat
Redhat advanced Cluster Security
Redhat quay
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Redhat Advanced Cluster Security Quay Quay 3
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-11T07:39:56.092Z

Reserved: 2026-08-11T06:19:12.439Z

Link: CVE-2026-19519

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-11T08:17:20.880

Modified: 2026-08-11T08:17:20.880

Link: CVE-2026-19519

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-08T00:00:00Z

Links: CVE-2026-19519 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:19:55Z

Weaknesses