UBUNTU-CVE-2024-23722

Source
https://ubuntu.com/security/CVE-2024-23722
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-23722.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2024-23722
Related
Published
2024-03-26T15:15:00Z
Modified
2025-02-04T04:32:35Z
Summary
[none]
Details

In Fluent Bit 2.1.8 through 2.2.1, a NULL pointer dereference can be caused via an invalid HTTP payload with the content type of x-www-form-urlencoded. It crashes and does not restart. This could result in logs not being delivered properly.

References

Affected packages

Ubuntu:24.04:LTS / netdata

Package

Name
netdata
Purl
pkg:deb/ubuntu/netdata@1.43.2-1build2?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.42.1-1
1.43.1-1
1.43.2-1
1.43.2-1build1
1.43.2-1build2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}