CVE-2024-21523
Last modified
CVE-2024-21523 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. All versions of the package images are vulnerable to Denial of Service (DoS) due to providing unexpected input types to several different functions. This makes it possible to reach an assert macro, leading to a process crash. **Note:** By providing some specific integer values (like 0) to the size function, it is possible to obtain a Segmentation fault error, leading to the process crash.. EPSS estimates a 0.60% chance of exploitation in the next 30 days.
Description
All versions of the package images are vulnerable to Denial of Service (DoS) due to providing unexpected input types to several different functions. This makes it possible to reach an assert macro, leading to a process crash. **Note:** By providing some specific integer values (like 0) to the size function, it is possible to obtain a Segmentation fault error, leading to the process crash.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-21523?
How severe is CVE-2024-21523?
How do I fix CVE-2024-21523?
Are you affected by CVE-2024-21523?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
