moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion.
References
Configurations
History
No history.
Information
Published : 2024-11-29 18:15
Updated : 2025-07-02 20:43
NVD link : CVE-2024-36621
Mitre link : CVE-2024-36621
CVE.ORG link : CVE-2024-36621
JSON object : View
Products Affected
mobyproject
- moby
CWE
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
