PT-2024-9588 · Docker+2 · Moby+3

Published

2024-11-29

·

Updated

2025-09-05

·

CVE-2024-36620

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions moby versions 25.0.0 through 26.0.2
Description The issue is related to a NULL Pointer Dereference in the daemon/images/image history.go file. This could potentially allow a remote attacker to cause a denial of service.
Recommendations For moby versions 25.0.0 through 26.0.2, consider disabling the functionality related to daemon/images/image history.go until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-53828
BDU:2024-11295
CVE-2024-36620
GHSA-Q59J-VV4J-V33C
GO-2024-3311
OESA-2024-2507
OPENSUSE-SU-2024:14567-1

Affected Products

Astra Linux
Docker
Red Os
Moby