gist.github.com
https://gist.github.com/1047524396/5d44459edab5fafcdf86b43909b81135 CVE-2024-36621
Moby Race Condition vulnerability
Description
moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 4, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
github.com/moby/mobyBrowse Go / github.com/moby/moby | GitHub Advisory | Before 26.0.0 · Fixed in 26.0.0 | affected |
References
6github.com
https://github.com/advisories/GHSA-2mj3-vfvx-fc43 github.com
https://github.com/moby/moby github.com
https://github.com/moby/moby/blob/v25.0.5/builder/builder-next/adapters/snapshot/layer.go github.com
https://github.com/moby/moby/commit/37545cc644344dcb576cba67eb7b6f51a463d31e nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-36621