By the Year
In 2022 there have been 0 vulnerabilities in Storageproject Storage . Last year Storage had 1 security vulnerability published. Right now, Storage is on track to have less security vulnerabilities in 2022 than it did last year.
It may take a day or so for new Storage vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Storageproject Storage Security Vulnerabilities
A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1
6.5 - Medium
- April 01, 2021
A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which never finishes. An attacker could use this vulnerability to craft a malicious image, which when downloaded and stored by an application using containers/storage, would then cause a deadlock leading to a Denial of Service (DoS).