CVE-2024-36623

HIGH8.1EPSS 0.05%

Moby Race Condition vulnerability

Published: 11/29/2024Modified: 2/4/2026
Also known as:GHSA-gh5c-3h97-2f3qCGA-r6j8-q9qv-pwh9GO-2024-3305

Description

moby v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application crashes.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
osvCVSS 3.1HIGH8.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

References (8)