{"id":"CVE-2026-83603","summary":"Netdata: Local Root via ndsudo Arbitrary socket_path → fail2ban-client Pickle RCE","details":"Netdata is an open source observability tool. Prior to 2.10.4, the setuid-root ndsudo helper command fail2ban-client-status-socket in src/collectors/utils/ndsudo.c accepts a caller-controlled --socket_path from the low-privileged netdata service account. The account can direct root fail2ban-client to a malicious UNIX socket, and fail2ban/client/csocket.py CSocket.receive() passes the returned data to pickle.loads(), allowing attacker-controlled code to execute as root on systems with fail2ban-client installed. This issue is fixed in version 2.10.4 and nightly build 2.10.0-782-nightly.","aliases":["GHSA-qwh9-pq27-993w"],"modified":"2026-09-25T08:24:15.631284Z","published":"2026-09-22T17:01:56.465Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-502","CWE-73"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/83xxx/CVE-2026-83603.json"},"references":[{"type":"WEB","url":"https://github.com/netdata/netdata/releases/tag/v2.10.4"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/83xxx/CVE-2026-83603.json"},{"type":"ADVISORY","url":"https://github.com/netdata/netdata/security/advisories/GHSA-qwh9-pq27-993w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-83603"},{"type":"FIX","url":"https://github.com/netdata/netdata/commit/9bced8d46464bd0fe01b0b5f8c63c4ac24e9b060"},{"type":"FIX","url":"https://github.com/netdata/netdata/pull/22745"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/netdata/netdata","events":[{"introduced":"0"},{"fixed":"9bced8d46464bd0fe01b0b5f8c63c4ac24e9b060"},{"fixed":"245283237171400672a9ad914f5785ba8bc0fa5c"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.10.4"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v2.10.3","v2.10.2","v2.10.1","v2.10.0","v2.9.0","v2.8.0","v2.7.0","v2.6.0","v2.5.0","v2.4.0","v2.3.0","v2.2.0","v2.1.0","v2.0.0","v1.47.0","v1.99.0","v1.46.0","v1.45.0","v1.44.0","v1.43.0","v1.42.0","v1.41.0","v1.40.0","v1.39.0","v1.38.0","v1.37.0","v1.36.0","v1.35.0","v1.34.0","1.34.0","v1.33.1","v1.33.0","v1.32.1","1.32.1","v1.32.0","v1.31.0","v1.30.1","v1.30.0","v1.29.3","v1.29.2","v1.29.1","v1.29.0","v1.27.0_0104103941","v1.28.0","v1.27.0","v1.26.0","v1.25.0","v1.24.0","v1.23.2","v1.23.1_infiniband","v1.23.1","v1.23.0","v1.22.1","v1.22.0","v1.21.1","v1.21.0","v1.20.0","v1.19.0","v1.18.1","v1.18.0","v1.17.1","v1.17.0","v1.16.1","v1.16.0","v1.15.0","v1.14.0","v1.14.0-rc0","v1.13.0","v1.12.2","v1.12.1","v1.12.0","v1.12.0-rc3","v1.12.0-rc2","v1.12.0-rc1","v1.12.0-rc0","v1.11.1","v1.11.0","v1.10.0","untagged-10d59b9e5fa68b9500e1","v1.9.0","v1.8.0","v1.7.0","v1.6.0","v1.5.0","v1.4.0","v1.3.0","v1.2.0","v1.1.0","v1.0.0","v1.0rc","v0.2","v0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-83603.json","vanir_signatures_modified":"2026-09-25T08:24:15Z","vanir_signatures":[{"digest":{"line_hashes":["145502671235432794023844567434327174601","304372119545992816617684381727583601007","73450841204797344488191033477509041071","197961079879052031371221752648773688265","70713990567942265007864732196086641108","22828932509653172035916910630643388984","6267422522785001239350338372685845854","183648796998145560939801182552564360690","307918585819356045600218673644898913427","101354288147399063875143168779890117314","273237870677431648392506380041709126428"],"threshold":0.9},"id":"CVE-2026-83603-319ac665","signature_type":"Line","signature_version":"v1","source":"https://github.com/netdata/netdata/commit/9bced8d46464bd0fe01b0b5f8c63c4ac24e9b060","target":{"file":"src/collectors/utils/ndsudo.c"},"deprecated":false}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"}]}