Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-2mj3-vfvx-fc43 | Moby Race Condition vulnerability |
Ubuntu USN |
USN-7474-1 | Docker vulnerabilities |
Wed, 02 Jul 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mobyproject
Mobyproject moby |
|
| CPEs | cpe:2.3:a:mobyproject:moby:25.0.5:*:*:*:*:*:*:* | |
| Vendors & Products |
Mobyproject
Mobyproject moby |
Wed, 04 Dec 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 04 Dec 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Mon, 02 Dec 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | moby: Race Condition in Moby's Snapshot Layer Handling | |
| Weaknesses | CWE-362 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Fri, 29 Nov 2024 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-12-04T17:13:36.018Z
Reserved: 2024-05-30T00:00:00.000Z
Link: CVE-2024-36621
Updated: 2024-12-04T17:13:31.141Z
Status : Analyzed
Published: 2024-11-29T18:15:07.993
Modified: 2025-07-02T20:43:30.047
Link: CVE-2024-36621
OpenCVE Enrichment
No data.
Github GHSA
Ubuntu USN