Intel

AIKIDO-2024-10239

fluent-bit is vulnerable to Memory Leak

Memory Leak Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Sep 2, 2024

35

Low Risk

This Affects:

osfluent-bit
1.0.0 - 3.1.6
Fixed in 3.1.7
Are you affected? Scan for Free

TL;DR

Affected versions of the package leak memory and resources, creating a potential Denial of Service vulnerability. Malicious users can exploit these leaks to cause the system to become unresponsive.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

fluent-bit is vulnerable to Memory Leak in versions 1.0.0 - 3.1.6.

How to fix this

Upgrade the fluent-bit library to the patch version.