Database/Control plane, storage & DevOps
Fluent Bit: "Linguistic Lumberjack" - memory corruption parsing trace requests in the embedded HTTP server
CVSS 9.8CVE-2024-4323Control plane, storage & DevOpscurated
Impact
"Linguistic Lumberjack" - memory corruption parsing trace requests in the embedded HTTP server -> RCE
Who can reach it
Network (remote)
What to do
Data-plane: DaemonSet on every GPU node - fleet rollout + disable /api/v1/traces
References
Related entries
- Fluent Bit: Prometheus Remote Write input crashes on a Content-Length: 0 packetCVE-2024-50608 · Fluent BitHigh
- Fluent Bit: OpenTelemetry input plugin crashes on a Content-Length: 0 packetCVE-2024-50609 · Fluent BitHigh
- Fortinet FortiManager: "FortiJump" - missing authentication in fgfmdCVE-2024-47575 · Fortinet FortiManagerCritical
- GitHub Enterprise Server: Forged SAML response with encrypted assertions enabledCVE-2024-4985 · GitHub Enterprise ServerCritical
- Linux NFS server (nfsd, laundromat vs free_stateid race): A race between the delegation laundromat and a client-issuedCVE-2024-50106 · Linux NFS server (nfsd, laundromat vs free_stateid race)Critical
- HPE Insight Remote Support (directory traversal to RCE): Directory traversal allowing unauthenticated remote codeCVE-2024-53676 · HPE Insight Remote Support (directory traversal to RCE)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.