Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-36621

Опубликовано: 29 нояб. 2024
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion.

A flaw was found in Moby's builder-next snapshot layer management. This vulnerability allows attackers to trigger resource leaks or exhaustion via concurrent builds calling the EnsureLayer function.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Multicluster Engine for Kubernetesmulticluster-engine/agent-service-rhel8Not affected
Multicluster Engine for Kubernetesmulticluster-engine/assisted-service-8-rhel8Not affected
Multicluster Engine for Kubernetesmulticluster-engine/assisted-service-9-rhel9Not affected
OpenShift Service Mesh 2openshift-service-mesh/istio-rhel8-operatorNot affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel8Not affected
Red Hat Ceph Storage 5rhceph/rhceph-5-dashboard-rhel8Not affected
Red Hat Ceph Storage 6rhceph/rhceph-6-dashboard-rhel9Not affected
Red Hat Ceph Storage 7rhceph/grafana-rhel9Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-agent-installer-api-server-rhel8Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-consoleNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-362
https://bugzilla.redhat.com/show_bug.cgi?id=2329522moby: Race Condition in Moby's Snapshot Layer Handling

EPSS

Процентиль: 16%
0.00053
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 1 года назад

moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion.

CVSS3: 6.5
nvd
больше 1 года назад

moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion.

CVSS3: 6.5
msrc
больше 1 года назад

moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion.

CVSS3: 6.5
debian
больше 1 года назад

moby v25.0.5 is affected by a Race Condition in builder/builder-next/a ...

CVSS3: 6.5
github
больше 1 года назад

Moby Race Condition vulnerability

EPSS

Процентиль: 16%
0.00053
Низкий

5.3 Medium

CVSS3