Impact
The vulnerability arises when the Ankaios agent accepts protobuf messages with a declared length that exceeds the system’s limits. A malicious payload specifying an excessive length results in an unbounded memory allocation that can cause the agent process to abort, leading to a denial of service and disrupting orchestration for affected workloads.
Affected Systems
Eclipse Foundation’s Ankaios, versions 0.1.0 through 1.0.1.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity; the EPSS score is not available, so the current likelihood of exploitation cannot be precisely quantified. The vulnerability is not listed in CISA’s KEV, suggesting no public exploits are known. Attackers must have the ability to send messages through the Control Interface FIFO—typically a workload granted such access can craft a malicious message. No remote exploitation vector is documented in the description, so the risk is confined to contexts where Control Interface privileges exist.
OpenCVE Enrichment