Debian Package Tracker
Register | Log in
Subscribe

netdata

real-time performance monitoring (metapackage)

Choose email to subscribe with

general
  • source: netdata (main)
  • version: 1.37.1-2
  • maintainer: Daniel Baumann (DMD)
  • uploaders: Federico Ceratto [DMD] – Lennart Weller [DMD]
  • arch: all
  • std-ver: 4.6.2
  • VCS: Git (Browse)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.29.3-4
  • oldstable: 1.37.1-2
versioned links
  • 1.29.3-4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.37.1-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • netdata
  • netdata-apache2
  • netdata-core
  • netdata-core-no-sse
  • netdata-plugins-bash
  • netdata-plugins-python
  • netdata-web
package is gone
This package is not in any development repository. This probably means that the package has been removed (or has been renamed). Thus the information here is of little interest ... the package is going to disappear unless someone takes it over and reintroduces it.
action needed
7 security issues in bookworm high

There are 7 open security issues in bookworm.

7 important issues:
  • CVE-2026-83597: Netdata is an open source observability tool. From version 2.0.0 until 2.10.4, Netdata Windows Agent MSI repair launches powershell.exe and wevtutil.exe as elevated interactive processes in the initiating user's desktop session. A low-privileged local user who triggers repair can interact with or hijack those visible process windows to execute arbitrary commands with SYSTEM privileges. This issue is fixed in stable version 2.10.4.
  • CVE-2026-83598: Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Agent MSI repair, powershell.exe runs as SYSTEM without -NoProfile and loads %USERPROFILE%\Documents\WindowsPowerShell\Microsoft.PowerShell_profile.ps1 from the low-privileged user who initiated repair. Commands placed in that profile before repair therefore execute with SYSTEM privileges. This vulnerability is fixed in 2.10.4.
  • CVE-2026-83599: Netdata is an open source observability tool. Prior to 2.11.0, Netdata's unauthenticated WebSocket server negotiates permessage-deflate before authentication, and src/web/websocket/websocket-compression.c allows websocket_client_decompress_message() to grow decompressed output toward WS_MAX_DECOMPRESSED_SIZE without enforcing a compressed-to-decompressed ratio. Small highly compressed frames can therefore cause large server-side allocations, and repeated concurrent connections can exhaust memory and terminate monitoring. This vulnerability is fixed in 2.11.0.
  • CVE-2026-83600: Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized CHART SLOT value that str2ull_encoded passes to pluginsd_rrdset_cache_put_to_slot in src/plugins.d/pluginsd_internals.h. The accepted slot drives reallocz to request an approximately 16 GiB chart-pointer array, and allocation failure invokes fatal and aborts the parent Netdata agent, repeatedly disabling centralized monitoring while stream access persists. This issue is fixed in version 2.10.4 and nightly build 2.10.0-782-nightly.
  • CVE-2026-83601: Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized DIMENSION SLOT value that str2ull_encoded passes to pluginsd_rrddim_put_to_slot in src/plugins.d/pluginsd_internals.h without an upper bound. prd_array_create in src/database/rrdset-pluginsd-array.h can then wrap the size_t allocation calculation while retaining the original large array size, causing the subsequent initialization loop to write beyond the undersized heap allocation and crash the parent agent. This issue is fixed in version 2.10.4 and nightly build 2.10.0-782-nightly.
  • CVE-2026-83602: Netdata is an open source observability tool. From 2.0.0 until 2.11.0, Netdata registers /api/v3/settings in src/web/api/v3/web_api_v3.c with HTTP_ACL_NOCHECK and HTTP_ACCESS_ANONYMOUS_DATA, causing unauthenticated PUT requests handled by src/web/api/v3/api_v3_settings.c to bypass operator-configured allow dashboard from IP restrictions. A network-reachable caller can persist attacker-controlled JSON in {varlib}/settings/default.json, manipulate its version counter, and use repeated near-20 MiB writes to consume disk space, although the file does not control collection or security policy. This vulnerability is fixed in 2.11.0.
  • CVE-2026-83603: Netdata is an open source observability tool. Prior to 2.10.4, the setuid-root ndsudo helper command fail2ban-client-status-socket in src/collectors/utils/ndsudo.c accepts a caller-controlled --socket_path from the low-privileged netdata service account. The account can direct root fail2ban-client to a malicious UNIX socket, and fail2ban/client/csocket.py CSocket.receive() passes the returned data to pickle.loads(), allowing attacker-controlled code to execute as root on systems with fail2ban-client installed. This issue is fixed in version 2.10.4 and nightly build 2.10.0-782-nightly.
Created: 2026-09-23 Last update: 2026-09-23 07:30
news
[rss feed]
  • [2025-06-09] Removed 2.0.3+dfsg-5 from unstable (Debian FTP Masters)
  • [2025-05-25] Accepted netdata 2.0.3+dfsg-5 (source) into unstable (Bastian Germann) (signed by: bage@debian.org)
  • [2025-05-23] Accepted netdata 2.0.3+dfsg-4 (source) into unstable (Daniel Baumann)
  • [2025-05-21] Accepted netdata 2.0.3+dfsg-3 (source) into unstable (Daniel Baumann)
  • [2025-05-21] Accepted netdata 2.0.3+dfsg-2 (source) into experimental (Daniel Baumann)
  • [2024-11-25] Accepted netdata 2.0.3+dfsg-1 (source) into experimental (Daniel Baumann)
  • [2024-11-09] Accepted netdata 1.47.5-1 (source) into unstable (Daniel Baumann)
  • [2024-09-30] Accepted netdata 1.47.2-1 (source) into unstable (Daniel Baumann)
  • [2024-09-11] Accepted netdata 1.47.1-1 (source) into unstable (Daniel Baumann)
  • [2024-08-26] Accepted netdata 1.47.0-1 (source) into unstable (Daniel Baumann)
  • [2024-07-25] Accepted netdata 1.46.3-2 (source) into experimental (Daniel Baumann)
  • [2024-07-24] Accepted netdata 1.46.3-1 (source) into experimental (Daniel Baumann)
  • [2024-03-09] Accepted netdata 1.44.3-2 (source) into unstable (Daniel Baumann)
  • [2024-03-09] Accepted netdata 1.44.3-1 (source) into unstable (Daniel Baumann)
  • [2023-12-07] netdata REMOVED from testing (Debian testing watch)
  • [2023-11-06] netdata 1.43.2-1 MIGRATED to testing (Debian testing watch)
  • [2023-11-01] Accepted netdata 1.43.2-1 (source) into unstable (Daniel Baumann)
  • [2023-11-01] netdata 1.43.1-1 MIGRATED to testing (Debian testing watch)
  • [2023-10-26] Accepted netdata 1.43.1-1 (source) into unstable (Daniel Baumann)
  • [2023-10-22] netdata 1.43.0-1 MIGRATED to testing (Debian testing watch)
  • [2023-10-17] Accepted netdata 1.43.0-1 (source) into unstable (Daniel Baumann)
  • [2023-09-24] netdata 1.42.4-1 MIGRATED to testing (Debian testing watch)
  • [2023-09-18] Accepted netdata 1.42.4-1 (source) into unstable (Daniel Baumann)
  • [2023-09-18] netdata 1.42.3-1 MIGRATED to testing (Debian testing watch)
  • [2023-09-18] netdata 1.42.3-1 MIGRATED to testing (Debian testing watch)
  • [2023-09-13] Accepted netdata 1.42.3-1 (source) into unstable (Daniel Baumann)
  • [2023-09-09] netdata 1.42.2-1 MIGRATED to testing (Debian testing watch)
  • [2023-09-04] Accepted netdata 1.42.2-1 (source) into unstable (Daniel Baumann)
  • [2023-08-22] netdata 1.42.1-1 MIGRATED to testing (Debian testing watch)
  • [2023-08-22] netdata 1.42.1-1 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • buildd: logs
  • popcon
  • browse source code
  • other distros
  • security tracker
  • screenshots

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing