Executive brief
Netdata is an open source monitoring and observability platform. A setuid-root helper command in Netdata prior to 2.10.4 accepts caller-controlled socket paths and passes data to Python's pickle.loads(), allowing arbitrary code execution as root on systems with fail2ban-client installed. An attacker with access to the low-privileged netdata service account can exploit this to gain root-level control.
Technical details
The ndsudo setuid-root helper in src/collectors/utils/ndsudo.c accepts an attacker-controlled --socket_path parameter from the netdata service account and passes it to fail2ban-client. The fail2ban/client/csocket.py CSocket.receive() method deserializes returned data with pickle.loads() without validation, enabling arbitrary code execution as root. This requires fail2ban-client to be installed and accessible, and the netdata service to be running.
Affected products
- Netdata Netdata prior to 2.10.4
Timeline
- 2026-09-22: disclosed
- 2026-06-16: patched: Fixed in version 2.10.4 and nightly build 2.10.0-782-nightly