PT-2024-21382 · Unknown · Fluent-Bit

Published

2024-02-26

·

Updated

2025-05-13

·

CVE-2024-26455

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions fluent-bit version 2.2.2
Description The issue is a Use-After-Free vulnerability located in the /fluent-bit/plugins/custom calyptia/calyptia.c file.
Recommendations For fluent-bit version 2.2.2, consider disabling the custom calyptia plugin as a temporary workaround until a patch is available. Restrict access to the vulnerable calyptia.c file to minimize the risk of exploitation. Avoid using the affected plugin until the issue is resolved.

Exploit

Fix

Use After Free

Weakness Enumeration

Related Identifiers

AZL-35449
AZL-35472
BIT-FLUENT-BIT-2024-26455
CVE-2024-26455

Affected Products

Fluent-Bit