HIGH8.1
GHSA-gh5c-3h97-2f3q
Moby Race Condition vulnerability
Quick fix
GHSA-gh5c-3h97-2f3q — github.com/moby/moby: upgrade to the fixed version with the command below.
go get github.com/moby/moby@v25.0.4Details
moby v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application crashes.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-36623[ADVISORY]
- https://github.com/moby/moby/commit/5689dabfb357b673abdb4391eef426f297d7d1bb[WEB]
- https://github.com/moby/moby/commit/8e3bcf19748838b30e34d612832d1dc9d90363b8[WEB]
- https://gist.github.com/1047524396/c192c0159a19bf58a4373b696467dc29[WEB]
- https://github.com/moby/moby[PACKAGE]
- https://github.com/moby/moby/blob/v25.0.3/pkg/streamformatter/streamformatter.go#L115[WEB]