moby: Race Condition in Moby's streamformatter Package
Published Nov 29, 2024
8.7
HIGHCVSS 4.0
EPSS 0.64%
Description
moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application crashes.
Affected products
No data.
- ≤ 25.0.3
No data.
Multicluster Engine for Kubernetes
multicluster-engine/agent-service-rhel8
Not affected
Multicluster Engine for Kubernetes
multicluster-engine/assisted-service-8-rhel8
Not affected
Multicluster Engine for Kubernetes
multicluster-engine/assisted-service-9-rhel9
Not affected
OpenShift Service Mesh 2
openshift-service-mesh/istio-rhel8-operator
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/acm-grafana-rhel8
Not affected
Red Hat Ceph Storage 5
rhceph/rhceph-5-dashboard-rhel8
Not affected
Red Hat Ceph Storage 6
rhceph/rhceph-6-dashboard-rhel9
Not affected
Red Hat Ceph Storage 7
rhceph/grafana-rhel9
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-agent-installer-api-server-rhel9
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-console
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Multicluster Engine for Kubernetes | multicluster-engine/agent-service-rhel8 | Not affected | n/a |
| Multicluster Engine for Kubernetes | multicluster-engine/assisted-service-8-rhel8 | Not affected | n/a |
| Multicluster Engine for Kubernetes | multicluster-engine/assisted-service-9-rhel9 | Not affected | n/a |
| OpenShift Service Mesh 2 | openshift-service-mesh/istio-rhel8-operator | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/acm-grafana-rhel8 | Not affected | n/a |
| Red Hat Ceph Storage 5 | rhceph/rhceph-5-dashboard-rhel8 | Not affected | n/a |
| Red Hat Ceph Storage 6 | rhceph/rhceph-6-dashboard-rhel9 | Not affected | n/a |
| Red Hat Ceph Storage 7 | rhceph/grafana-rhel9 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-agent-installer-api-server-rhel9 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-console | Not affected | n/a |
github.com/moby/moby
Go
Introduced 0 Fixed 26.0.0+incompatible
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/moby/moby | 0 | 26.0.0+incompatible |
Remediation
Red Hat statement
Red Hat Enterprise Linux is not vulnerable to this CVE, as it does not affect the versions or configurations of the moby package used in its distributions.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (9)
- https://access.redhat.com/security/cve/CVE-2024-36623 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2329519 Issue Tracking
- https://gist.github.com/1047524396/c192c0159a19bf58a4373b696467dc29 Third Party Advisory
- https://github.com/advisories/GHSA-gh5c-3h97-2f3q Advisory
- https://github.com/moby/moby/blob/v25.0.3/pkg/streamformatter/streamformatter.go#L115 Product
- https://github.com/moby/moby/commit/5689dabfb357b673abdb4391eef426f297d7d1bb Patch
- https://github.com/moby/moby/commit/8e3bcf19748838b30e34d612832d1dc9d90363b8 Patch
- https://nvd.nist.gov/vuln/detail/CVE-2024-36623
- https://www.cve.org/CVERecord?id=CVE-2024-36623
Change history (0)
No recorded changes yet.