CVE-2024-36621 is a race condition vulnerability in moby v25.0.5, specifically within the builder/builder-next/adapters/snapshot/layer.go component. This flaw allows for concurrent builds to trigger the EnsureLayer function, potentially leading to resource leaks and exhaustion. With a CVSS score of 6.5 (Medium), it can be exploited remotely with low attack complexity, resulting in high availability impact. Currently, there is no known active exploitation, public exploit code, or Metasploit/Nuclei modules, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
25.0.5CPE matchmatch criteria | cpe:2.3:a:mobyproject:moby:25.0.5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2024-36621
Dec 10, 2024Moby Race Condition vulnerability
Nov 29, 2024moby: Race Condition in Moby's Snapshot Layer Handling
Nov 29, 2024moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion.
Nov 12, 2024