CVE-2026-96609: Robur Albatross vulnerability
Robur Albatross 1.0.0 through 2.x before 2.7.2 does not limit use of the ring buffer, leading to an albatross-console loop with no recognized termination condition. This is only exploitable by users who can send console subscription commands to unikernels that produce sufficient log output to fill the ring buffer (1024 lines). It is not exploitable by unauthorized clients.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Robur Albatrossto a version that resolves this vulnerability.Fixed in 2.7.2
Event History
Frequently Asked Questions
Who can exploit this issue?
Only users authorized to send console subscription commands to affected unikernels can exploit it. Unauthorized clients cannot exploit the issue.
What conditions are required to trigger the loop?
The targeted unikernel must produce enough log output to fill the 1024-line ring buffer after a console subscription is established. Under those conditions, albatross-console can enter a loop with no recognized termination condition.
Which versions should be remediated?
Robur Albatross versions 1.0.0 through 2.x before 2.7.2 are affected. Upgrade to 2.7.2 or later.