gist.github.com
https://gist.github.com/1047524396/f08816669701ab478a265a811d2c89b2 CVE-2024-36620
NULL Pointer Dereference on moby image history
Description
moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 4, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
github.com/moby/mobyBrowse Go / github.com/moby/moby | GitHub Advisory | 25.0.0 to < 26.1.0 · Fixed in 26.1.0 | affected |
References
6github.com
https://github.com/moby/moby github.com
https://github.com/moby/moby/blob/v26.0.2/daemon/images/image_history.go github.com
https://github.com/moby/moby/commit/ab570ab3d62038b3d26f96a9bb585d0b6095b9b4 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-36620 pkg.go.dev
https://pkg.go.dev/vuln/GO-2024-3311