Incorrect Resource Transfer Between Spheres in moby - CVE-2024-29018

 

Incorrect Resource Transfer Between Spheres in moby - CVE-2024-29018

Published: March 20, 2024 / Updated: March 21, 2024


Vulnerability identifier: #VU87658
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-29018
CWE-ID: CWE-669
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application within external DNS requests from "internal" networks. A remote attacker can gain unauthorized access to sensitive information on the system.


Affected software

moby
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Containers Module
openSUSE Leap
Ubuntu
openEuler
Astronomer with IBM
Guardium Data Security Center (GDSC)
APEX Cloud Platform for Microsoft Azure
IBM Edge Application Manager
Migration Toolkit for Containers
golang-github-docker-docker-dev (Ubuntu package)
docker.io (Ubuntu package)
docker-engine
docker-engine-debuginfo
docker-engine-debugsource
docker-stable-bash-completion
docker-stable-debuginfo
docker-stable
docker-stable-zsh-completion
docker-stable-rootless-extras
docker-stable-fish-completion
docker-debuginfo
docker
docker-bash-completion
docker-rootless-extras
docker-zsh-completion
docker-fish-completion
IBM Concert Software
IBM Cloud Pak for Security
APEX Cloud Platform for Red Hat OpenShift
IBM Cloud Pak System

How to mitigate CVE-2024-29018

Install updates from vendor's website.

moby - addressed in versions 23.0.11, 25.0.5, 26.0.0 rc3, 26.0.0
Astronomer with IBM - update to 1.0.1
Guardium Data Security Center (GDSC) - update to 3.7.2
IBM Edge Application Manager - update to 4.5.6
golang-github-docker-docker-dev (Ubuntu package) - addressed in versions Ubuntu Pro, 26.1.4+dfsg2-1ubuntu1.1
docker.io (Ubuntu package) - addressed in versions Ubuntu Pro, 26.1.3-0ubuntu1.1
IBM Concert Software - update to 1.0.1
APEX Cloud Platform for Microsoft Azure - addressed in versions 01.04.01.00, 01.05.01.00
Migration Toolkit for Containers - update to 1.8.4
IBM Cloud Pak for Security - update to 1.11.2.0
IBM Cloud Pak System - update to 2.3.4.1
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
docker-engine - addressed in versions 18.09.0-264, 18.09.0-334, 18.09.0-335
docker-engine-debuginfo - addressed in versions 18.09.0-334, 18.09.0-335
docker-engine-debugsource - addressed in versions 18.09.0-334, 18.09.0-335
docker-stable-bash-completion - addressed in versions 24.0.9_ce-1.11.1, 24.0.9_ce-1.32.1, 24.0.9_ce-150000.1.11.1, 24.0.9_ce-150000.1.15.1, 24.0.9_ce-150000.1.39.1
docker-stable-debuginfo - addressed in versions 24.0.9_ce-1.11.1, 24.0.9_ce-1.32.1, 24.0.9_ce-150000.1.11.1, 24.0.9_ce-150000.1.15.1, 24.0.9_ce-150000.1.39.1
docker-stable - addressed in versions 24.0.9_ce-1.11.1, 24.0.9_ce-1.32.1, 24.0.9_ce-150000.1.11.1, 24.0.9_ce-150000.1.15.1, 24.0.9_ce-150000.1.39.1
docker-stable-zsh-completion - addressed in versions 24.0.9_ce-150000.1.11.1, 24.0.9_ce-150000.1.15.1, 24.0.9_ce-150000.1.39.1
docker-stable-rootless-extras - addressed in versions 24.0.9_ce-150000.1.11.1, 24.0.9_ce-150000.1.15.1, 24.0.9_ce-150000.1.39.1
docker-stable-fish-completion - addressed in versions 24.0.9_ce-150000.1.11.1, 24.0.9_ce-150000.1.15.1, 24.0.9_ce-150000.1.39.1
docker-debuginfo - addressed in versions 27.5.1_ce-98.123.1, 27.5.1_ce-98.126.1, 27.5.1_ce-150000.215.3, 27.5.1_ce-150000.218.1
docker - addressed in versions 27.5.1_ce-98.123.1, 27.5.1_ce-98.126.1, 27.5.1_ce-150000.215.3, 27.5.1_ce-150000.218.1
docker-bash-completion - addressed in versions 27.5.1_ce-98.123.1, 27.5.1_ce-98.126.1, 27.5.1_ce-150000.215.3, 27.5.1_ce-150000.218.1
docker-rootless-extras - addressed in versions 27.5.1_ce-150000.215.3, 27.5.1_ce-150000.218.1
docker-zsh-completion - addressed in versions 27.5.1_ce-150000.215.3, 27.5.1_ce-150000.218.1
docker-fish-completion - addressed in versions 27.5.1_ce-150000.215.3, 27.5.1_ce-150000.218.1

External References

Related Security Bulletins