Database/Control plane, storage & DevOps
GitLab CE/EE: double free parsing a crafted CI/CD regular expression gives code execution on the server
Impact
An authenticated GitLab user who can supply a CI/CD configuration can trigger a double free in the regular-expression parser and execute arbitrary code on the GitLab server itself. The CVSS vector marks the scope as changed, meaning the compromise reaches beyond the GitLab process. For a GPU fleet this is a build-and-deploy plane compromise: whoever controls the CI server controls the container images, Helm charts and runner credentials that land on GPU nodes, and GitLab runners themselves often hold registry and cluster tokens. The privilege needed is low - any user with push or project-configuration rights.
Who can reach it
Any authenticated GitLab user able to commit or edit a CI/CD configuration file in a project they can write to. Network-reachable; no administrator role required.
What to do
Upgrade to GitLab 19.2.7, 19.3.3 or 19.4.1 per the 19.4.1 patch release and restart the GitLab services. Self-managed operators should treat this as a same-day patch for an internet-reachable instance; no node reboot is required, but expect a short outage of the CI plane during the upgrade and review runner job history and token use if the instance was exposed.
References
Related entries
- GitLab CE/EE: integer overflow compiling a crafted CI/CD regular expression gives code execution on the serverCVE-2026-93577 · GitLab CE/EE (CI/CD config regular-expression compiler)Critical
- lldpd (lldp_decode, management addresses): Buffer overflow in lldpd's LLDP decoder via large management addressesCVE-2015-8011 · lldpd (lldp_decode, management addresses)Critical
- Lantronix xPrintServer: The device ships with a hardcoded root account baked into every unit of a given firmware lineCVE-2016-4325 · Lantronix xPrintServerCritical
- HPE iLO3 / iLO4: Multiple unspecified flaws allowing remote information disclosure, data modification and DoSCVE-2016-4375 · HPE iLO3 / iLO4Critical
- Tridium Niagara AX (<=3.8) and Niagara 4 (<=4.4) framework: Log into the Niagara platform with a disabled account nameCVE-2017-16748 · Tridium Niagara AX (<=3.8) and Niagara 4 (<=4.4) frameworkCritical
- Lenovo / IBM Integrated Management Module 2 (IMM2) web administration service: The overflow is inside theCVE-2017-3774 · Lenovo / IBM Integrated Management Module 2 (IMM2) web administration serviceCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.