GHSA-mjcv-p78q-w5fw: Medium severity go/github.com/moby/sys/user vulnerability

Published Oct 8, 2026
·
Updated

A denial-of-service (DoS) vulnerability exists in github.com/moby/sys/user before v0.4.1 when parsing specially crafted user or group database files. An attacker able to supply a malicious /etc/passwd or /etc/group-style file may cause excessive memory consumption, potentially resulting in process termination due to Out Of Memory (OOM) conditions.

This issue is related to containerd [CVE-2026-47262] / GHSA-jpcc-p29g-p8mq, which describes one practical exploitation path through processing untrusted container image content. Applications using github.com/moby/sys/user to parse untrusted user or group database files may be similarly affected.

Impact

github.com/moby/sys/user versions before v0.4.1 do not place sufficient limits on entries while parsing user and group database files. A specially crafted file may cause excessive memory consumption, potentially leading to process termination due to Out Of Memory (OOM) conditions.

Applications that use github.com/moby/sys/user to parse user-supplied or otherwise untrusted /etc/passwd or /etc/group files may be affected. The severity depends on whether an attacker can influence the contents of files being parsed.

Patches

This issue is fixed in github.com/moby/sys/user v0.4.1. Users should upgrade to v0.4.1 or later.

Workarounds

Avoid parsing attacker-controlled /etc/passwd or /etc/group-style files with affected versions of github.com/moby/sys/user.

Applications that must process untrusted user or group database files should validate and limit accepted input before parsing. Upgrading to v0.4.1 or later is the recommended remediation.

References

containerd CVE-2026-47262 / GHSA-jpcc-p29g-p8mq: https://github.com/containerd/containerd/security/advisories/GHSA-jpcc-p29g-p8mq Fix in github.com/moby/sys/user: https://github.com/moby/sys/user/commit/210d32ba2bcb4544ee968c7f31249fe59796e60b

Affected Software

1 affected componentFixes available
go/github.com/moby/sys/user<=0.4.0
0.4.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/github.com/moby/sys/user to a version that resolves this vulnerability.

    Fixed in 0.4.1
  2. Upgrade

    Upgrade github.com/moby/sys/user to a version that resolves this vulnerability.

    Fixed in v0.4.1
  3. Compensating control

    Avoid parsing attacker-controlled /etc/passwd or /etc/group-style files with affected versions of github.com/moby/sys/user; validate and limit accepted user or group database input before parsing.

Event History

Oct 8, 2026
Advisory Published
via GitHub·04:08 PM
Data Sourced
via GitHub·04:08 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which applications are realistically exposed?

Applications using github.com/moby/sys/user before v0.4.1 are exposed when they parse user-supplied or otherwise untrusted /etc/passwd- or /etc/group-style files. Processing untrusted container image content is identified as one practical exploitation path.

2

What does an attacker need to exploit this issue?

An attacker needs the ability to supply a specially crafted user or group database file that the affected application will parse. Exploitation can consume excessive memory and may terminate the process through an OOM condition.

3

How should affected deployments be remediated?

Upgrade github.com/moby/sys/user to v0.4.1 or later. The affected versions are those before v0.4.1.

4

How can teams determine whether they are affected?

Identify whether the application depends on github.com/moby/sys/user at a version before v0.4.1, and determine whether it parses untrusted passwd- or group-style data. Review container image processing paths as well, since untrusted image content is a documented practical path.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203