github.com/moby/moby: NULL Pointer Dereference in Moby
Published Nov 29, 2024
5.7
MEDIUMCVSS 4.0
EPSS 0.82%
Description
moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.
Affected products
No data.
- ≥ 25.0.0 · ≤ 26.0.2
No data.
Red Hat OpenShift Container Platform 4.16
openshift4/ose-agent-installer-api-server-rhel9:v4.16.0-202503121138.p0.gef6fa80.assembly.stream.el9
Fixed · RHSA-2025:3301
Red Hat OpenShift Container Platform 4.17
openshift4/ose-agent-installer-api-server-rhel9:v4.17.0-202502172135.p0.g9145aec.assembly.stream.el9
Fixed · RHSA-2025:1703
Multicluster Engine for Kubernetes
multicluster-engine/agent-service-rhel8
Affected
Multicluster Engine for Kubernetes
multicluster-engine/assisted-service-8-rhel8
Affected
Multicluster Engine for Kubernetes
multicluster-engine/assisted-service-9-rhel9
Affected
OpenShift Service Mesh 2
openshift-service-mesh/istio-rhel8-operator
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/acm-grafana-rhel8
Not affected
Red Hat Ceph Storage 5
rhceph/rhceph-5-dashboard-rhel8
Not affected
Red Hat Ceph Storage 6
rhceph/rhceph-6-dashboard-rhel9
Not affected
Red Hat Ceph Storage 7
rhceph/grafana-rhel10
Not affected
Red Hat Ceph Storage 7
rhceph/grafana-rhel9
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-console-rhel9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 4.16 | openshift4/ose-agent-installer-api-server-rhel9:v4.16.0-202503121138.p0.gef6fa80.assembly.stream.el9 | Fixed | RHSA-2025:3301 |
| Red Hat OpenShift Container Platform 4.17 | openshift4/ose-agent-installer-api-server-rhel9:v4.17.0-202502172135.p0.g9145aec.assembly.stream.el9 | Fixed | RHSA-2025:1703 |
| Multicluster Engine for Kubernetes | multicluster-engine/agent-service-rhel8 | Affected | n/a |
| Multicluster Engine for Kubernetes | multicluster-engine/assisted-service-8-rhel8 | Affected | n/a |
| Multicluster Engine for Kubernetes | multicluster-engine/assisted-service-9-rhel9 | Affected | n/a |
| OpenShift Service Mesh 2 | openshift-service-mesh/istio-rhel8-operator | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/acm-grafana-rhel8 | Not affected | n/a |
| Red Hat Ceph Storage 5 | rhceph/rhceph-5-dashboard-rhel8 | Not affected | n/a |
| Red Hat Ceph Storage 6 | rhceph/rhceph-6-dashboard-rhel9 | Not affected | n/a |
| Red Hat Ceph Storage 7 | rhceph/grafana-rhel10 | Not affected | n/a |
| Red Hat Ceph Storage 7 | rhceph/grafana-rhel9 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-console-rhel9 | Not affected | n/a |
github.com/moby/moby
Go
Introduced 25.0.0+incompatible Fixed 26.1.0+incompatible
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/moby/moby | 25.0.0+incompatible | 26.1.0+incompatible |
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (10)
- https://access.redhat.com/security/cve/CVE-2024-36620 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2329534 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-3404 Advisory
- https://gist.github.com/1047524396/f08816669701ab478a265a811d2c89b2 Third Party Advisory
- https://github.com/advisories/GHSA-q59j-vv4j-v33c Advisory
- https://github.com/moby/moby/blob/v26.0.2/daemon/images/image_history.go#L48 Product
- https://github.com/moby/moby/commit/ab570ab3d62038b3d26f96a9bb585d0b6095b9b4 Patch
- https://nvd.nist.gov/vuln/detail/CVE-2024-36620
- https://pkg.go.dev/vuln/GO-2024-3311
- https://www.cve.org/CVERecord?id=CVE-2024-36620
Change history (0)
No recorded changes yet.