CVE-2024-36623

moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application crashes.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mobyproject:moby:*:*:*:*:*:*:*:*

History

02 Jul 2025, 20:36

Type Values Removed Values Added
Summary (en) moby v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application crashes. (en) moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application crashes.
First Time Mobyproject
Mobyproject moby
CPE cpe:2.3:a:mobyproject:moby:*:*:*:*:*:*:*:*
References
  • () https://github.com/moby/moby/commit/8e3bcf19748838b30e34d612832d1dc9d90363b8 - Patch
References () https://gist.github.com/1047524396/c192c0159a19bf58a4373b696467dc29 - () https://gist.github.com/1047524396/c192c0159a19bf58a4373b696467dc29 - Third Party Advisory
References () https://github.com/moby/moby/blob/v25.0.3/pkg/streamformatter/streamformatter.go#L115 - () https://github.com/moby/moby/blob/v25.0.3/pkg/streamformatter/streamformatter.go#L115 - Product
References () https://github.com/moby/moby/commit/5689dabfb357b673abdb4391eef426f297d7d1bb - () https://github.com/moby/moby/commit/5689dabfb357b673abdb4391eef426f297d7d1bb - Patch

Information

Published : 2024-11-29 18:15

Updated : 2025-07-02 20:36


NVD link : CVE-2024-36623

Mitre link : CVE-2024-36623

CVE.ORG link : CVE-2024-36623


JSON object : View

Products Affected

mobyproject

  • moby
CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')