Docker is a product for you to build, ship and run any application as a lightweight container.
Security Fix(es):
moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.(CVE-2024-36620)
moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion.(CVE-2024-36621)
moby v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application crashes.(CVE-2024-36623)
{ "severity": "High" }
{ "aarch64": [ "libnetwork-25.0.3-22.oe2403.aarch64.rpm", "moby-25.0.3-22.oe2403.aarch64.rpm", "moby-client-25.0.3-22.oe2403.aarch64.rpm", "moby-debuginfo-25.0.3-22.oe2403.aarch64.rpm", "moby-engine-25.0.3-22.oe2403.aarch64.rpm" ], "src": [ "moby-25.0.3-22.oe2403.src.rpm" ], "x86_64": [ "libnetwork-25.0.3-22.oe2403.x86_64.rpm", "moby-25.0.3-22.oe2403.x86_64.rpm", "moby-client-25.0.3-22.oe2403.x86_64.rpm", "moby-debuginfo-25.0.3-22.oe2403.x86_64.rpm", "moby-engine-25.0.3-22.oe2403.x86_64.rpm" ] }