Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-36620

Опубликовано: 29 нояб. 2024
Источник: redhat
CVSS3: 6.5

Описание

moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.

A flaw was found in Moby. This vulnerability allows an attacker to cause a NULL pointer dereference, potentially leading to a denial of service via improper handling in the image history functionality.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Multicluster Engine for Kubernetesmulticluster-engine/agent-service-rhel8Affected
Multicluster Engine for Kubernetesmulticluster-engine/assisted-service-8-rhel8Affected
Multicluster Engine for Kubernetesmulticluster-engine/assisted-service-9-rhel9Affected
OpenShift Service Mesh 2openshift-service-mesh/istio-rhel8-operatorNot affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel8Not affected
Red Hat Ceph Storage 5rhceph/rhceph-5-dashboard-rhel8Not affected
Red Hat Ceph Storage 6rhceph/rhceph-6-dashboard-rhel9Not affected
Red Hat Ceph Storage 7rhceph/grafana-rhel9Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-consoleNot affected
Red Hat OpenShift Container Platform 4.16openshift4/ose-agent-installer-api-server-rhel9FixedRHSA-2025:330103.04.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2329534github.com/moby/moby: NULL Pointer Dereference in Moby

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
7 месяцев назад

moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.

CVSS3: 6.5
msrc
6 месяцев назад

Описание отсутствует

CVSS3: 6.5
debian
7 месяцев назад

moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via d ...

CVSS3: 3.3
redos
6 месяцев назад

Уязвимость docker-ce

CVSS3: 6.5
github
7 месяцев назад

NULL Pointer Dereference on moby image history

6.5 Medium

CVSS3