Fluent Bit 1.6.10 has a NULL pointer dereference when an flb_malloc return value is not validated by flb_avro.c or http_server/api/v1/metrics.c.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://github.com/fluent/fluent-bit/issues/3044 | third party advisory exploit |
https://github.com/fluent/fluent-bit/pull/3045 | exploit third party advisory patch |
https://github.com/fluent/fluent-bit/pull/3047 | third party advisory patch |