CVE-2024-23722: Null Pointer Dereference
In Fluent Bit 2.1.8 through 2.2.1 a NULL pointer dereference can be caused via an invalid HTTP payload with the content type of x-www-form-urlencoded. It crashes and does not restart. This could result in logs not being delivered properly.
Other sources
In Fluent Bit 2.1.8 through 2.2.1, a NULL pointer dereference can be caused via an invalid HTTP payload with the content type of x-www-form-urlencoded. It crashes and does not restart. This could result in logs not being delivered properly.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23722?
CVE-2024-23722 is a high severity vulnerability due to its potential to cause application crashes and logging issues.
How do I fix CVE-2024-23722?
To fix CVE-2024-23722, update Fluent Bit to version 2.2.2 or later.
What causes the NULL pointer dereference in CVE-2024-23722?
The NULL pointer dereference in CVE-2024-23722 is caused by an invalid HTTP payload with the content type of x-www-form-urlencoded.
What are the potential impacts of CVE-2024-23722?
CVE-2024-23722 can lead to application crashes, resulting in logs not being delivered properly, which may affect system monitoring.
Which versions of Fluent Bit are affected by CVE-2024-23722?
Fluent Bit versions 2.1.8 through 2.2.1 are affected by CVE-2024-23722.