/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-6m4j-gwc9-vjg7

Published

Last updated

https://images.chainguard.dev/security/CGA-6m4j-gwc9-vjg7
Package

netavark

RepositoryWolfi
Latest Update
Pending upstream fix
Aliases
  • CVE-2024-12224
  • GHSA-h97m-ww89-6jmq

Severity

8.8

High

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2024-12224

Updates

Status

Pending upstream fix

Impact

This vulnerability is related to the 'mozim' dependency, which is currently at its latest version, though is requiring an older version of dhcproto, which is in turn requiring an older version of trust-dns-proto which is requiring idna 0.2.3 (still vulnerable). Indeed the newest version of trust-dns-proto is requiring idna 0.4.0 (also vulnerable) Waiting on upstream (mozim, dhcproto, and trust-dns-proto) to update requirements to using non-vulnerable idna

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing