Microsoft Security Response Center guidance
Vendor revision: Aug 12, 2026CBL-Mariner Releases
Vendor-listed releases
- 24.0.9-11
- 25.0.3-8
Vulnerability intelligence
CVE-2024-36621 and is rated Medium severity with a CVSS score of 6.5. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
CBL-Mariner Releases
Vendor-listed releases
moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion.
Source: NVD