Executive brief
Malcolm is a network traffic analysis tool that processes uploaded PCAP and log files. When an authenticated user uploads a highly compressed file (such as a gzip bomb) in single-stream formats like .gz or .bz2, the system fails to enforce decompression limits and can exhaust the shared Docker storage volume, causing service outages for all users analyzing network traffic.
Technical details
The vulnerability exists in scripts/safe-extract.py, which dispatches archive extraction based on file type. The _extract_libarchive() function enforces ARCHIVE_EXTRACT_MAX_ENTRIES, ARCHIVE_EXTRACT_MAX_DEPTH, and ARCHIVE_EXTRACT_MAX_TOTAL_BYTES (default 4 GiB) limits for multi-entry archives, but the _extract_raw_stream() and _extract_lzip() functions that handle single-stream compressed formats (.gz, .bz2, .xz, .lzma, .lz) perform unbounded decompression with no size accounting. An authenticated user with upload privileges can upload a small, highly compressible file (e.g., a 2 MB gzip bomb) that decompresses to multiple gigabytes, exhausting disk space on the shared /zeek Docker volume used by OpenSearch, Logstash, Arkime, and Zeek. The fix is available in version 26.08.0, and patched versions also addressed related issues in versions 26.06.1 and 26.07.0.
Affected products
- CISA Malcolm <=26.07.1
Timeline
- 2026-07-28: disclosed
- 2026-08-18: advisory
- 2026-08-18: patched: Fixed in Malcolm v26.08.0