Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2mj3-vfvx-fc43

Опубликовано: 29 нояб. 2024
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 6.5

Описание

Moby Race Condition vulnerability

moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion.

Пакеты

Наименование

github.com/moby/moby

go
Затронутые версииВерсия исправления

< 26.0.0

26.0.0

EPSS

Процентиль: 39%
0.00173
Низкий

8.7 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 6.5
ubuntu
10 месяцев назад

moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion.

CVSS3: 5.3
redhat
10 месяцев назад

moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion.

CVSS3: 6.5
nvd
10 месяцев назад

moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion.

CVSS3: 6.5
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 6.5
debian
10 месяцев назад

moby v25.0.5 is affected by a Race Condition in builder/builder-next/a ...

EPSS

Процентиль: 39%
0.00173
Низкий

8.7 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-362