CVE-2026-72854MediumCVSS 5.3

msgpack-c Integer Overflow in msgpack_unpacker_expand_buffer Causes a False-Success Undersized Reservation

Published
August 25, 2026
Last Modified
—

🔗 CVE IDs covered (1)

🎯 Affected products4

  • azl3 fluent-bit 3.1.10-6 on Azure Linux 3.0
  • azl3 fluent-bit 3.1.10-7 on Azure Linux 3.0
  • azl3 lttng-tools 2.13.11-1 on Azure Linux 3.0
  • azl3 msgpack 3.3.0-1 on Azure Linux 3.0

✅ Remediation

KBRelease Notes (Security Update)

🔗 References (2)