CVE-2024-11991

Source
https://cve.org/CVERecord?id=CVE-2024-11991
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-11991.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-11991
Aliases
  • GHSA-9rhg-3qf8-hrv3
Published
2024-12-09T15:15:12.203Z
Modified
2026-04-10T05:12:29.023556Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Motoko's incremental garbage collector is impacted by an uninitialized memory access bug, caused by incorrect use of write barriers in a few locations. This vulnerability could potentially allow unauthorized read or write access to a Canister's memory. However, exploiting this bug requires the Canister to enable the incremental garbage collector or enhanced orthogonal persistence, which are non-default features in Motoko.

References

Affected packages

Git / github.com/dfinity/motoko

Affected ranges

Type
GIT
Repo
https://github.com/dfinity/motoko
Events
Database specific
{
    "versions": [
        {
            "introduced": "0.9.0"
        },
        {
            "fixed": "0.13.4"
        }
    ]
}

Affected versions

0.*
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.13.3
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-11991.json"