CVE-2026-61801: github.com/moby/sys/user has a possible DoS via unbounded parsing of user and group database files

Published Oct 8, 2026
·
Updated

A denial-of-service (DoS) vulnerability exists in github.com/moby/sys/user before v0.4.1 when parsing specially crafted user or group database files. An attacker able to supply a malicious /etc/passwd or /etc/group-style file may cause excessive memory consumption, potentially resulting in process termination due to Out Of Memory (OOM) conditions.

This issue is related to containerd [CVE-2026-47262] / GHSA-jpcc-p29g-p8mq, which describes one practical exploitation path through processing untrusted container image content. Applications using github.com/moby/sys/user to parse untrusted user or group database files may be similarly affected.

Impact

github.com/moby/sys/user versions before v0.4.1 do not place sufficient limits on entries while parsing user and group database files. A specially crafted file may cause excessive memory consumption, potentially leading to process termination due to Out Of Memory (OOM) conditions.

Applications that use github.com/moby/sys/user to parse user-supplied or otherwise untrusted /etc/passwd or /etc/group files may be affected. The severity depends on whether an attacker can influence the contents of files being parsed.

Patches

This issue is fixed in github.com/moby/sys/user v0.4.1. Users should upgrade to v0.4.1 or later.

Workarounds

Avoid parsing attacker-controlled /etc/passwd or /etc/group-style files with affected versions of github.com/moby/sys/user.

Applications that must process untrusted user or group database files should validate and limit accepted input before parsing. Upgrading to v0.4.1 or later is the recommended remediation.

References

containerd CVE-2026-47262 / GHSA-jpcc-p29g-p8mq: https://github.com/containerd/containerd/security/advisories/GHSA-jpcc-p29g-p8mq Fix in github.com/moby/sys/user: https://github.com/moby/sys/user/commit/210d32ba2bcb4544ee968c7f31249fe59796e60b

Other sources

The github.com/moby/sys/user package provides Go utilities for parsing and looking up entries in Unix-style user and group database files. Versions before 0.4.1 do not sufficiently limit entries when parsing /etc/passwd- or /etc/group-style files, allowing an attacker who can supply a specially crafted file to cause excessive memory consumption and potentially terminate the affected process due to an out-of-memory condition. This issue is patched in version 0.4.1. As a workaround, avoid parsing attacker-controlled user or group database files, or validate and limit untrusted input before parsing it.

— MITRE

Affected Software

1 affected componentFixes available
go/github.com/moby/sys/user<=0.4.0
0.4.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/github.com/moby/sys/user to a version that resolves this vulnerability.

    Fixed in 0.4.1
  2. Upgrade

    Upgrade github.com/moby/sys/user to a version that resolves this vulnerability.

    Fixed in 0.4.1
  3. Compensating control

    Avoid parsing attacker-controlled /etc/passwd- or /etc/group-style files; when untrusted user or group database files must be processed, validate and limit the accepted input before parsing.

Event History

Oct 8, 2026
Advisory Published
via GitHub·04:08 PM
Data Sourced
via GitHub·04:08 PM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·04:22 PM
Data Sourced
via MITRE·04:22 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are realistically exposed to this issue?

Applications using github.com/moby/sys/user before v0.4.1 are affected when they parse user-supplied or otherwise untrusted /etc/passwd- or /etc/group-style files. A practical path can involve processing untrusted container image content.

2

What does an attacker need to exploit the vulnerability?

An attacker needs the ability to supply a specially crafted user or group database file that the application passes to the vulnerable parser. Exploitation does not require user interaction, but the attacker must be able to influence the parsed file content.

3

What is the impact if exploitation succeeds?

The crafted file can trigger excessive memory consumption during parsing. This can cause an out-of-memory condition and terminate the affected process.

4

What should be done if the application cannot be upgraded immediately?

Avoid parsing user or group database files from user-controlled or otherwise untrusted sources until an upgrade is possible. In particular, review workflows that process untrusted container image content or accept passwd- and group-style files.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203