rootpwn

critical · CVSS v3 9.1 · CVSS v4 7.1

CVE-2026-96609

Robur Albatross versions 1.0.0 through 2.7.1 allow unlimited ring buffer usage, causing an infinite console loop that can exhaust system res

Overview

Robur Albatross versions 1.0.0 through 2.7.1 allow unlimited ring buffer usage, causing an infinite console loop that can exhaust system resources. The flaw is exploitable only by clients that can send console subscription commands to the unikernel. It can lead to a denial‑of‑service for operators managing affected unikernels.

Description

Robur Albatross 1.0.0 through 2.x before 2.7.2 does not limit use of the ring buffer, leading to an albatross-console loop with no recognized termination condition. This is only exploitable by users who can send console subscription commands to unikernels that produce sufficient log output to fill the ring buffer (1024 lines). It is not exploitable by unauthorized clients.

Impact

Availability is compromised as the ring buffer can be filled with up to 1024 log lines, exhausting memory and CPU resources. Operators of affected unikernels may experience service interruption. Confidentiality and integrity remain unaffected.

Remediation

Upgrade to Robur Albatross 2.7.2 or later where the ring buffer limit is enforced. If upgrading is not immediately possible, restrict console subscription commands to trusted users, throttle log generation, or reduce the ring buffer size via configuration. Monitor system logs for signs of buffer exhaustion.

Risk context

The vulnerability is rated critical with a CVSS v3 score of 9.1 and no EPSS data, indicating a high likelihood of exploitation in environments where console subscriptions are enabled. Defenders should treat this as a high‑priority issue.

Affected products

  • Robur Albatross 1.0.0-2.7.1

Scores

Severity
critical
CVSS v2
7.5
CVSS v3
9.1
CVSS v4
7.1
EPSS

Denial of Service Ring Buffer Unikernel Robur Albatross Critical Availability Log Exhaustion

← All CVEs