CVE-2024-36621

Severity CVSS v4.0:
Pending analysis
Type:
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Publication date:
29/11/2024
Last modified:
02/07/2025

Description

moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mobyproject:moby:25.0.5:*:*:*:*:*:*:*