CVE-2026-85201: Eclipse Ankaios vulnerability
In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-delimited protobuf message received through the Control Interface FIFO. A workload granted Control Interface access can specify an excessive message length, causing an unbounded memory allocation that may abort the Ankaios agent process. This results in loss of orchestration services for workloads managed by the affected agent.
Affected Software
Event History
Frequently Asked Questions
Which workloads can trigger the issue?
A workload must be granted access to the Control Interface FIFO. Workloads without that access are not described as able to send the malformed length-delimited protobuf message.
What is the operational impact if exploitation succeeds?
The affected agent may perform an unbounded memory allocation and abort. This disrupts orchestration services for workloads managed by that agent.
Which versions are affected, and is a fixed release available?
Eclipse Ankaios versions 0.1.0 through 1.0.1 are affected. The provided release reference identifies version 1.0.2 as the subsequent release.