CVE-2024-36620 is a NULL Pointer Dereference vulnerability affecting moby versions 25.0.0 through 26.0.2, specifically within the daemon/images/image_history.go component. Rated Medium severity (CVSS 6.5), this vulnerability can lead to high availability impact (denial of service) with low attack complexity, requiring low privileges and no user interaction over a network. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog, though it has garnered minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 25.0.0, <= 26.0.2CPE matchmatch criteria | cpe:2.3:a:mobyproject:moby:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2024-36620
Dec 10, 2024NULL Pointer Dereference on moby image history
Nov 29, 2024github.com/moby/moby: NULL Pointer Dereference in Moby
Nov 29, 2024moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.
Nov 12, 2024