CVE-2024-7884 is a memory leak vulnerability in the DFINITY canister_developer_kit_for_the_internet_computer (ic_cdk) affecting Rust-based canisters. It occurs when canister methods are called, timers are used, or heartbeat functions are triggered, leading to the persistence of internal state references and a gradual accumulation of memory on the canister's heap. With a CVSS score of 7.5 (High), this vulnerability can result in denial of service due to heap memory exhaustion, though it requires no user interaction or complex attack vectors. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.8.0, < 0.8.2CPE matchmatch criteria | cpe:2.3:a:dfinity:canister_developer_kit_for_the_internet_computer:*:*:*:*:*:rust:*:* | ||
>= 0.9.0, < 0.9.3CPE matchmatch criteria | cpe:2.3:a:dfinity:canister_developer_kit_for_the_internet_computer:*:*:*:*:*:rust:*:* | ||
>= 0.11.0, < 0.11.6CPE matchmatch criteria | cpe:2.3:a:dfinity:canister_developer_kit_for_the_internet_computer:*:*:*:*:*:rust:*:* | ||
>= 0.12.0, < 0.12.2CPE matchmatch criteria | cpe:2.3:a:dfinity:canister_developer_kit_for_the_internet_computer:*:*:*:*:*:rust:*:* | ||
>= 0.13.0, < 0.13.5CPE matchmatch criteria | cpe:2.3:a:dfinity:canister_developer_kit_for_the_internet_computer:*:*:*:*:*:rust:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.