Junglewise Threat Intelligence

CVE-2026-83601: Netdata heap buffer overflow in pluginsd DIMENSION SLOT parsing

CVE-2026-83601 · Severity: medium · CVSS 6.5 · Published 2026-09-22

Technologies: Netdata. Vendors: Netdata.

Executive brief

Netdata is an open-source monitoring and observability platform. An authenticated child agent can trigger a heap buffer overflow in the parent agent by sending an oversized DIMENSION SLOT value, causing the parent to crash or potentially corrupt memory. The vulnerability requires the attacker to be authenticated as a child agent in the Netdata streaming protocol.

Technical details

An integer wraparound in the allocation calculation within prd_array_create allows an oversized slot value to bypass size validation, resulting in a heap buffer overflow during array initialization. The vulnerability is exploitable by any authenticated child agent or plugin that can send crafted pluginsd protocol messages. Netdata 2.10.4 and later include bounds checking on slot values to prevent this issue.

Affected products

  • Netdata Netdata before 2.10.4

Timeline

  • 2026-09-22: disclosed: CVE-2026-83601 published
  • 2026-07-15: patched: Fix merged in commit 034a774 (cherry-picked from 883928b)
  • 2026-06-08: patched: Fix authored and available in nightly build 2.10.0-782-nightly

References

Related threats