CVE-2024-26455: Use After Free
Published Feb 26, 2024
·Updated
fluent-bit 2.2.2 contains a Use-After-Free vulnerability in /fluent-bit/plugins/customcalyptia/calyptia.c.
Affected Software
6 affected componentsFixes available
Fluent Bit Fluent Bit
Treasuredata Fluent Bit=2.2.2
Microsoft azl3 fluent-bit 2.2.2-1
Microsoft cbl2 fluent-bit 2.2.3-7
Microsoft azl3 fluent-bit 3.0.3-1
Microsoft cbl2 fluent-bit 2.2.3-1
Event History
Feb 26, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Mar 4, 2024
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-26455?
CVE-2024-26455 has been classified as a high severity Use-After-Free vulnerability.
2
How do I fix CVE-2024-26455?
To fix CVE-2024-26455, update to a version of Fluent Bit that contains the patch for this vulnerability.
3
What versions of Fluent Bit are affected by CVE-2024-26455?
Fluent Bit version 2.2.2 is affected by CVE-2024-26455, which includes the Use-After-Free vulnerability.
4
What is the impact of CVE-2024-26455 on system security?
CVE-2024-26455 can potentially lead to unauthorized memory access, which may compromise system integrity or confidentiality.
5
Where can I find more information about CVE-2024-26455?
Detailed information about CVE-2024-26455 can be found in security bulletins or vulnerability databases that track CVE entries.