Description

moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion.

INFO

Published Date :

2024-11-29T00:00:00.000Z

Last Modified :

2024-12-04T17:13:36.018Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2024-36621 vulnerability.

Vendors Products
Mobyproject
  • Moby

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact