跳转到帖子

Amazon Linux AMI 2: CVE-2024-24790: Security patch for amazon-ecr-credential-helper, amazon-ssm-agent, containerd, docker, golang, nerdctl, runc (Multiple Advisories)

recommended_posts

发布于
  • Members

Amazon Linux AMI 2: CVE-2024-24790: Security patch for amazon-ecr-credential-helper, amazon-ssm-agent, containerd, docker, golang, nerdctl, runc (Multiple Advisories)

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
06/05/2024
Created
06/26/2024
Added
06/26/2024
Modified
01/28/2025

Description

The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.

Solution(s)

  • amazon-linux-ami-2-upgrade-amazon-ecr-credential-helper
  • amazon-linux-ami-2-upgrade-amazon-ecr-credential-helper-debuginfo
  • amazon-linux-ami-2-upgrade-amazon-ssm-agent
  • amazon-linux-ami-2-upgrade-containerd
  • amazon-linux-ami-2-upgrade-containerd-debuginfo
  • amazon-linux-ami-2-upgrade-containerd-stress
  • amazon-linux-ami-2-upgrade-docker
  • amazon-linux-ami-2-upgrade-docker-debuginfo
  • amazon-linux-ami-2-upgrade-golang
  • amazon-linux-ami-2-upgrade-golang-bin
  • amazon-linux-ami-2-upgrade-golang-docs
  • amazon-linux-ami-2-upgrade-golang-misc
  • amazon-linux-ami-2-upgrade-golang-shared
  • amazon-linux-ami-2-upgrade-golang-src
  • amazon-linux-ami-2-upgrade-golang-tests
  • amazon-linux-ami-2-upgrade-nerdctl
  • amazon-linux-ami-2-upgrade-nerdctl-debuginfo
  • amazon-linux-ami-2-upgrade-runc
  • amazon-linux-ami-2-upgrade-runc-debuginfo

References

  • https://attackerkb.com/topics/cve-2024-24790
  • AL2/ALAS-2024-2576
  • AL2/ALAS-2024-2618
  • AL2/ALAS-2024-2645
  • AL2/ALASDOCKER-2024-041
  • AL2/ALASDOCKER-2024-043
  • AL2/ALASDOCKER-2024-045
  • AL2/ALASDOCKER-2024-046
  • AL2/ALASECS-2024-040
  • AL2/ALASECS-2024-042
  • AL2/ALASECS-2024-043
  • AL2/ALASNITRO-ENCLAVES-2024-042
  • AL2/ALASNITRO-ENCLAVES-2024-044
  • AL2/ALASNITRO-ENCLAVES-2024-046
  • AL2/ALASNITRO-ENCLAVES-2024-047
  • CVE - 2024-24790
View more
  • 查看数 700
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…