CVE-2024-36623 is a race condition vulnerability in the streamformatter package of Moby (Docker Engine) versions up to 25.0.3. This flaw allows an authenticated attacker to trigger concurrent write operations, leading to data corruption or application crashes. Rated 8.1 HIGH, it has a low attack complexity and can result in high integrity and availability impacts. While no public exploits or active exploitation have been observed, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 25.0.3CPE matchmatch criteria | cpe:2.3:a:mobyproject:moby:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2024-36623
Dec 10, 2024Moby Race Condition vulnerability
Nov 29, 2024moby: Race Condition in Moby's streamformatter Package
Nov 29, 2024moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application crashes.
Nov 12, 2024