GPU VulnDB

Database/Control plane, storage & DevOps

MinIO (S3 Select): A crafted S3 Select CSV query makes MinIO allocate memory without bound until the process is

CVE-2026-39414Control plane, storage & DevOpscurated

Impact

A crafted S3 Select CSV query makes MinIO allocate memory without bound until the process is OOM-killed. One tenant issuing a single query takes down the shared object store for every job on the cluster.

Who can reach it

Any authenticated tenant that can issue S3 Select queries against the endpoint.

What to do

Upgrade to the release in GHSA-h749-fxx7-pwpg and restart the nodes. If S3 Select is not used by your workloads, deny SelectObjectContent in the bucket policy. Set a memory cgroup limit on the MinIO service so an allocation blowup restarts one node instead of destabilising the host.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.