Loop with Unreachable Exit Condition ('Infinite Loop') Affecting ruby4.0-fluentd-kubernetes-daemonset-1.19-kinesis package, versions <1.19.3.1.0-r0


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.32% (24th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-MINIMOSLATEST-RUBY40FLUENTDKUBERNETESDAEMONSET119KINESIS-17457643
  • published25 Jun 2026
  • disclosed24 Jun 2026

Introduced: 24 Jun 2026

CVE-2026-54904  (opens in a new tab)
CWE-835  (opens in a new tab)

How to fix?

Upgrade Minimos:latest ruby4.0-fluentd-kubernetes-daemonset-1.19-kinesis to version 1.19.3.1.0-r0 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream ruby4.0-fluentd-kubernetes-daemonset-1.19-kinesis package and not the ruby4.0-fluentd-kubernetes-daemonset-1.19-kinesis package as distributed by Minimos. See How to fix? for Minimos:latest relevant fixed versions and status.

concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::AtomicReference#update can enter a permanent busy retry loop when the current value is Float::NAN. The issue is caused by the interaction between AtomicReference#update, which retries until compare_and_set(old_value, new_value) succeeds; Numeric compare_and_set, which checks old == old_value before attempting the underlying atomic swap.; and Ruby NaN semantics, where Float::NAN == Float::NAN is always false. As a result, once an AtomicReference contains Float::NAN, calling #update repeatedly evaluates the caller's block and never returns. In services that store externally derived numeric values in an AtomicReference, this can cause CPU exhaustion or permanent request/job hangs. This vulnerability is fixed in 1.3.7.

CVSS Base Scores

version 3.1