CVE Vulnerabilities

CVE-2024-36620

NULL Pointer Dereference

Published: Nov 29, 2024 | Modified: Sep 05, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Ubuntu

moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Moby Mobyproject 25.0.0 (including) 26.0.2 (including)
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-agent-installer-api-server-rhel9:v4.16.0-202503121138.p0.gef6fa80.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.17 RedHat openshift4/ose-agent-installer-api-server-rhel9:v4.17.0-202502172135.p0.g9145aec.assembly.stream.el9 *

Potential Mitigations

References