PT-2025-6702 · Unknown+1 · Fluent-Bit+1

Faran Abdullah

·

Published

2025-02-18

·

Updated

2025-04-23

·

CVE-2024-50608

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Fluent Bit version 3.1.9
Description An issue was discovered in Fluent Bit when the Prometheus Remote Write input plugin is running and listening on an IP address and port. One can send a packet with Content-Length: 0 and it crashes the server. Improper handling of the case when Content-Length is 0 allows a user (with access to the endpoint) to perform a remote Denial of service attack. The crash happens because of a NULL pointer dereference when 0 (from the Content-Length) is passed to the function cfl sds len, which in turn tries to cast a NULL pointer into struct cfl sds. This is related to process payload metrics ng() at prom rw prot.c.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALT-PU-2025-3622
AZL-57074
AZL-57092
BDU:2025-02023
BIT-FLUENT-BIT-2024-50608
BIT-FLUENT-BIT-2024-50609
CVE-2024-50608

Affected Products

Alt Linux
Fluent-Bit