Impact
The Go package provides utilities for parsing Unix-style user and group database files. Prior to version 0.4.1 it does not limit the number of entries processed from files such as /etc/passwd or /etc/group. An attacker who can supply a specially crafted file may cause the parsing routine to allocate excessive amounts of memory, potentially leading to an out‑of‑memory situation and terminating the process that imports the library. The weakness is identified as an uncontrolled resource consumption flaw (CWE‑400 and CWE‑770).
Affected Systems
The vulnerability affects the moby:sys package at github.com/moby/sys/user. Any application using this package, in versions earlier than 0.4.1, is susceptible if it processes user or group database files that could be supplied by an attacker. The issue is resolved in release 0.4.1.
Risk and Exploitability
The CVSS base score is 5.5, indicating moderate severity. The EPSS score is not available, and the vulnerability is not currently listed in CISA KEV. The attack requires the ability to provide a crafted user or group file to the parsing function; it does not require network access or elevated privileges. An attacker who can influence the input can trigger denial of service by exhausting memory allocation.
OpenCVE Enrichment
Github GHSA