Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-36623

Опубликовано: 29 нояб. 2024
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application crashes.

A flaw was found in Moby's streamformatter package. This vulnerability allows data corruption or application crashes via multiple concurrent write operations triggered by a race condition.

Отчет

Red Hat Enterprise Linux is not vulnerable to this CVE, as it does not affect the versions or configurations of the moby package used in its distributions.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Multicluster Engine for Kubernetesmulticluster-engine/agent-service-rhel8Not affected
Multicluster Engine for Kubernetesmulticluster-engine/assisted-service-8-rhel8Not affected
Multicluster Engine for Kubernetesmulticluster-engine/assisted-service-9-rhel9Not affected
OpenShift Service Mesh 2openshift-service-mesh/istio-rhel8-operatorNot affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel8Not affected
Red Hat Ceph Storage 5rhceph/rhceph-5-dashboard-rhel8Not affected
Red Hat Ceph Storage 6rhceph/rhceph-6-dashboard-rhel9Not affected
Red Hat Ceph Storage 7rhceph/grafana-rhel9Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-agent-installer-api-server-rhel9Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-consoleNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-362
https://bugzilla.redhat.com/show_bug.cgi?id=2329519moby: Race Condition in Moby's streamformatter Package

EPSS

Процентиль: 47%
0.00239
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
10 месяцев назад

moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application crashes.

CVSS3: 8.1
nvd
10 месяцев назад

moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application crashes.

CVSS3: 8.1
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 8.1
debian
10 месяцев назад

moby through v25.0.3 has a Race Condition vulnerability in the streamf ...

CVSS3: 8.1
github
10 месяцев назад

Moby Race Condition vulnerability

EPSS

Процентиль: 47%
0.00239
Низкий

8.1 High

CVSS3