GHSA-mjcv-p78q-w5fw: Medium severity go/github.com/moby/sys/user vulnerability
A denial-of-service (DoS) vulnerability exists in github.com/moby/sys/user before v0.4.1 when parsing specially crafted user or group database files. An attacker able to supply a malicious /etc/passwd or /etc/group-style file may cause excessive memory consumption, potentially resulting in process termination due to Out Of Memory (OOM) conditions.
This issue is related to containerd [CVE-2026-47262] / GHSA-jpcc-p29g-p8mq, which describes one practical exploitation path through processing untrusted container image content. Applications using github.com/moby/sys/user to parse untrusted user or group database files may be similarly affected.
Impact
github.com/moby/sys/user versions before v0.4.1 do not place sufficient limits on entries while parsing user and group database files. A specially crafted file may cause excessive memory consumption, potentially leading to process termination due to Out Of Memory (OOM) conditions.
Applications that use github.com/moby/sys/user to parse user-supplied or otherwise untrusted /etc/passwd or /etc/group files may be affected. The severity depends on whether an attacker can influence the contents of files being parsed.
Patches
This issue is fixed in github.com/moby/sys/user v0.4.1. Users should upgrade to v0.4.1 or later.
Workarounds
Avoid parsing attacker-controlled /etc/passwd or /etc/group-style files with affected versions of github.com/moby/sys/user.
Applications that must process untrusted user or group database files should validate and limit accepted input before parsing. Upgrading to v0.4.1 or later is the recommended remediation.
References
containerd CVE-2026-47262 / GHSA-jpcc-p29g-p8mq: https://github.com/containerd/containerd/security/advisories/GHSA-jpcc-p29g-p8mq Fix in github.com/moby/sys/user: https://github.com/moby/sys/user/commit/210d32ba2bcb4544ee968c7f31249fe59796e60b
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/moby/sys/userto a version that resolves this vulnerability.Fixed in 0.4.1 - Upgrade
Upgrade
github.com/moby/sys/userto a version that resolves this vulnerability.Fixed in v0.4.1 - Compensating control
Avoid parsing attacker-controlled /etc/passwd or /etc/group-style files with affected versions of github.com/moby/sys/user; validate and limit accepted user or group database input before parsing.
Event History
Frequently Asked Questions
Which applications are realistically exposed?
Applications using github.com/moby/sys/user before v0.4.1 are exposed when they parse user-supplied or otherwise untrusted /etc/passwd- or /etc/group-style files. Processing untrusted container image content is identified as one practical exploitation path.
What does an attacker need to exploit this issue?
An attacker needs the ability to supply a specially crafted user or group database file that the affected application will parse. Exploitation can consume excessive memory and may terminate the process through an OOM condition.
How should affected deployments be remediated?
Upgrade github.com/moby/sys/user to v0.4.1 or later. The affected versions are those before v0.4.1.
How can teams determine whether they are affected?
Identify whether the application depends on github.com/moby/sys/user at a version before v0.4.1, and determine whether it parses untrusted passwd- or group-style data. Review container image processing paths as well, since untrusted image content is a documented practical path.