CVE-2022-23526High· 7.5▾ TwilightA flaw was found in Helm, a tool for managing Charts, a pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to NULL Pointer Dereference in the_chartutil_ package that could cause a segmentation violation. The _chartut…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.8%
Last analysed / modified upstream
5.3 → 7.5
medium → high
A flaw was found in Helm, a tool for managing Charts, a pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to NULL Pointer Dereference in the_chartutil_ package that could cause a segmentation violation. The chartutil package contains a parser that loads a JSON Schema validation files into structures Go can work with. Some schema files can cause array data structures to be created, causing a memory violation. Applications that use the chartutil package in the Helm SDK to parse a schema files may result in a denial of service.
helm: Denial of service through schema file — rated Moderate by Red Hat. Released 2022-12-15, updated 2026-09-17.
Affected:
Fixed:
No fix planned:
Not affected:
For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:
https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html https://access.redhat.com/errata/RHSA-2023:1646 For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:
https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html
You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags
The sha values for the release are:
(For x8… https://access.redhat.com/errata/RHSA-2023:1326 For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:
https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html
You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags.
The sha values for the release … https://access.redhat.com/errata/RHSA-2023:5006
Affected packages:
helm.sh/helm/v3 < 3.10.3Patched in:
helm.sh/helm/v3 3.10.3Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-80954Medium· 5.5kernel: i3c: Fix unlocked dereference of dev->desc in i3c_device_get_supported_xfer_mode() (CVE-2026-80954)
CVE-2026-89509Medium· 5.5kernel: RDMA/ionic: Embed counter driver data in rdma_counter allocation (CVE-2026-89509)
CVE-2026-89517Medium· 5.5kernel: sched_ext: Fix rq->core_pick corruption under core scheduling (CVE-2026-89517)
CVE-2026-89591Medium· 5.5kernel: accel/rocket: initialize job domain before cleanup paths (CVE-2026-89591)
CVE-2026-89552Medium· 4.1kernel: Linux kernel: Denial of Service via NULL pointer dereference in parameter handling (CVE-2026-89552)
CVE-2026-89592Medium· 5.5kernel: accel/rocket: fix NULL dereference and integer overflow in rocket_job_push() (CVE-2026-89592)