Storage Storageproject Storage

Do you want an email whenever new security vulnerabilities are reported in Storageproject Storage?

By the Year

In 2022 there have been 0 vulnerabilities in Storageproject Storage . Last year Storage had 1 security vulnerability published. Right now, Storage is on track to have less security vulnerabilities in 2022 than it did last year.

Year Vulnerabilities Average Score
2022 0 0.00
2021 1 6.50
2020 0 0.00
2019 0 0.00
2018 0 0.00

It may take a day or so for new Storage vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Storageproject Storage Security Vulnerabilities

A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1

CVE-2021-20291 6.5 - Medium - April 01, 2021

A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which never finishes. An attacker could use this vulnerability to craft a malicious image, which when downloaded and stored by an application using containers/storage, would then cause a deadlock leading to a Denial of Service (DoS).

Improper Locking

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Fedora Project Fedora or by Storageproject? Click the Watch button to subscribe.

subscribe