Improper Check for Unusual or Exceptional Conditions in BuildKit - CVE-2024-23650

 

Improper Check for Unusual or Exceptional Conditions in BuildKit - CVE-2024-23650

Published: February 2, 2024


Vulnerability identifier: #VU86039
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-23650
CWE-ID: CWE-754
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper error handling. A remote attacker can send specially crafted data to the application and perform a denial of service (DoS) attack.


Affected software

BuildKit
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Containers Module
openSUSE Leap
Juniper Secure Analytics (JSA)
IBM Qradar SIEM
toolbox
toolbox-tests
udica
buildkit
buildkit-doc
runc
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins
aardvark-dns
netavark
fuse-overlayfs
crun
skopeo-tests
skopeo
buildah
buildah-tests
containers-common
conmon
container-selinux
crit
criu
criu-devel
criu-libs
python3-criu
libslirp
libslirp-devel
python3-podman
podman
podman-catatonit
podman-gvproxy
podman-plugins
podman-remote
podman-tests
podman-docker
docker-stable
docker-stable-debuginfo
docker-stable-bash-completion
docker-stable-zsh-completion
docker-stable-fish-completion
docker-stable-rootless-extras
docker
app-containers/docker
docker-debuginfo
docker-bash-completion
cockpit-podman
IBM Concert Software
IBM Cloud Pak for Watson AIOps
IBM Security Verify Access

How to mitigate CVE-2024-23650

Install updates from vendor's website.

BuildKit - update to 0.12.5
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF01
toolbox - update to 0.0.99.5-2.0.1
toolbox-tests - update to 0.0.99.5-2.0.1
udica - update to 0.2.6-21
buildkit - update to 0.13.2-1
buildkit-doc - update to 0.13.2-1
IBM Concert Software - update to 1.0.1
runc - update to 1.1.12-1.0.1
slirp4netns - update to 1.2.3-1
oci-seccomp-bpf-hook - update to 1.2.10-1
containernetworking-plugins - update to 1.4.0-2.0.1
aardvark-dns - update to 1.10.0-2.0.1
netavark - update to 1.10.3-1.0.1
fuse-overlayfs - update to 1.13-1.0.1
crun - update to 1.14.3-2
skopeo-tests - update to 1.14.3-2.0.1
skopeo - update to 1.14.3-2.0.1
buildah - update to 1.33.7-1
buildah-tests - update to 1.33.7-1
containers-common - update to 1-81.0.1
conmon - update to 2.1.10-1
container-selinux - update to 2.229.0-2
crit - update to 3.18-5.0.1
criu - update to 3.18-5.0.1
criu-devel - update to 3.18-5.0.1
criu-libs - update to 3.18-5.0.1
python3-criu - update to 3.18-5.0.1
libslirp - update to 4.4.0-2
libslirp-devel - update to 4.4.0-2
IBM Cloud Pak for Watson AIOps - update to 4.4.1
python3-podman - update to 4.9.0-1
podman - update to 4.9.4-1.0.1
podman-catatonit - update to 4.9.4-1.0.1
podman-gvproxy - update to 4.9.4-1.0.1
podman-plugins - update to 4.9.4-1.0.1
podman-remote - update to 4.9.4-1.0.1
podman-tests - update to 4.9.4-1.0.1
podman-docker - update to 4.9.4-1.0.1
IBM Security Verify Access - update to 10.0.9
docker-stable - addressed in versions 24.0.9_ce-1.11.1, 24.0.9_ce-150000.1.11.1
docker-stable-debuginfo - addressed in versions 24.0.9_ce-1.11.1, 24.0.9_ce-150000.1.11.1
docker-stable-bash-completion - addressed in versions 24.0.9_ce-1.11.1, 24.0.9_ce-150000.1.11.1
docker-stable-zsh-completion - update to 24.0.9_ce-150000.1.11.1
docker-stable-fish-completion - update to 24.0.9_ce-150000.1.11.1
docker-stable-rootless-extras - update to 24.0.9_ce-150000.1.11.1
docker - update to 25.0.3-1
app-containers/docker - update to 25.0.4
docker-debuginfo - update to 27.5.1_ce-98.126.1
docker - update to 27.5.1_ce-98.126.1
docker-bash-completion - update to 27.5.1_ce-98.126.1
cockpit-podman - update to 84.1-1

External References

Related Security Bulletins