{"id":"GHSA-mjcv-p78q-w5fw","summary":"github.com/moby/sys/user has a possible DoS via unbounded parsing of user and group database files","details":"A denial-of-service (DoS) vulnerability exists in `github.com/moby/sys/user` before v0.4.1 when parsing specially crafted user or group database files. An attacker able to supply a malicious `/etc/passwd` or `/etc/group`-style file may cause excessive memory consumption, potentially resulting in process termination due to Out Of Memory (OOM) conditions.\n\nThis issue is related to containerd [CVE-2026-47262] / [GHSA-jpcc-p29g-p8mq](https://github.com/containerd/containerd/security/advisories/GHSA-jpcc-p29g-p8mq), which describes one practical exploitation path through processing untrusted container image content. Applications using `github.com/moby/sys/user` to parse untrusted user or group database files may be similarly affected.\n\n### Impact\n\n`github.com/moby/sys/user` versions before v0.4.1 do not place sufficient limits on entries while parsing user and group database files. A specially crafted file may cause excessive memory consumption, potentially leading to process termination due to Out Of Memory (OOM) conditions.\n\nApplications that use `github.com/moby/sys/user` to parse user-supplied or otherwise untrusted `/etc/passwd` or `/etc/group` files may be affected. The severity depends on whether an attacker can influence the contents of files being parsed.\n\n### Patches\n\nThis issue is fixed in `github.com/moby/sys/user` v0.4.1. Users should upgrade to v0.4.1 or later.\n\n### Workarounds\n\nAvoid parsing attacker-controlled `/etc/passwd` or `/etc/group`-style files with affected versions of `github.com/moby/sys/user`.\n\nApplications that must process untrusted user or group database files should validate and limit accepted input before parsing. Upgrading to v0.4.1 or later is the recommended remediation.\n\n### References\n\n* containerd CVE-2026-47262 / GHSA-jpcc-p29g-p8mq: https://github.com/containerd/containerd/security/advisories/GHSA-jpcc-p29g-p8mq\n* Fix in `github.com/moby/sys/user`: https://github.com/moby/sys/user/commit/210d32ba2bcb4544ee968c7f31249fe59796e60b","aliases":["CVE-2026-61801"],"modified":"2026-10-08T16:15:05.242761874Z","published":"2026-10-08T16:08:33Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-10-08T16:08:33Z","nvd_published_at":null,"cwe_ids":["CWE-400"]},"references":[{"type":"WEB","url":"https://github.com/moby/sys/security/advisories/GHSA-mjcv-p78q-w5fw"},{"type":"WEB","url":"https://github.com/moby/sys/pull/221"},{"type":"WEB","url":"https://github.com/moby/sys/commit/85a71bbe1faa36c552a960e6a5f3d0cfb632fbbe"},{"type":"PACKAGE","url":"https://github.com/moby/sys"}],"affected":[{"package":{"name":"github.com/moby/sys/user","ecosystem":"Go","purl":"pkg:golang/github.com/moby/sys/user"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.4.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-mjcv-p78q-w5fw/GHSA-mjcv-p78q-w5fw.json","last_known_affected_version_range":"\u003c= 0.4.0"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}