CVE-2026-35469

EUVD-2026-23298
spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count, the header count in parseHeaderValueBlock, and individual header field sizes — all read as 32-bit integers and used directly as allocation sizes with no bounds checking. Because SPDY header blocks are zlib-compressed, a small on-the-wire payload can decompress into large attacker-controlled values. A remote peer that can send SPDY frames to a service using spdystream can exhaust process memory and cause an out-of-memory crash with a single crafted control frame. This issue has been fixed in version 0.5.1.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 48.69%
Debian logo
Debian Releases
Debian Product
Codename
golang-github-docker-spdystream
bookworm
no-dsa
bullseye
ignored
forky
vulnerable
sid
vulnerable
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
golang-github-docker-spdystream
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
xenial
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
containerd
suse enterprise desktop 15 SP7
1.7.29-150000.142.1
fixed
suse enterprise sap 15 SP7
1.7.29-150000.142.1
fixed
suse enterprise server 15 SP4
1.7.29-150000.142.1
fixed
suse enterprise server 15 SP7
1.7.29-150000.142.1
fixed
containerd-ctr
suse enterprise sap 15 SP7
1.7.29-150000.142.1
fixed
suse enterprise server 15 SP4
1.7.29-150000.142.1
fixed
suse enterprise server 15 SP7
1.7.29-150000.142.1
fixed
containerd-devel
suse enterprise sap 15 SP7
1.7.29-150000.142.1
fixed
suse enterprise server 15 SP4
1.7.29-150000.142.1
fixed
suse enterprise server 15 SP7
1.7.29-150000.142.1
fixed
kubevirt-manifests
suse enterprise sap 15 SP7
1.7.4-150700.3.30.1
fixed
suse enterprise server 15 SP7
1.7.4-150700.3.30.1
fixed
kubevirt-virtctl
suse enterprise sap 15 SP7
1.7.4-150700.3.30.1
fixed
suse enterprise server 15 SP7
1.7.4-150700.3.30.1
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
cert-manager
Azure Linux 3.0
0:1.12.15-7.azl3
fixed
containerd2
Azure Linux 3.0
0:2.0.0-19.azl3
fixed
containerized-data-importer
Azure Linux 3.0
0:1.62.0-4.azl3
fixed
cri-tools
Azure Linux 3.0
0:1.32.0-5.azl3
fixed
docker-buildx
Azure Linux 3.0
0:0.14.0-12.azl3
fixed
docker-compose
Azure Linux 3.0
0:2.27.0-10.azl3
fixed
keda
Azure Linux 3.0
0:2.14.1-12.azl3
fixed
kubernetes
Azure Linux 3.0
0:1.30.10-23.azl3
fixed
kubevirt
Azure Linux 3.0
0:1.7.1-3.azl3
fixed
kured
Azure Linux 3.0
0:1.15.0-4.azl3
fixed
moby-containerd-cc
Azure Linux 3.0
0:1.7.7-12.azl3
fixed
References