{"id":"AZL-57086","summary":"CVE-2024-50609 affecting package fluent-bit for versions less than 3.0.6-2","details":"An issue was discovered in Fluent Bit 3.1.9. When the OpenTelemetry input plugin is running and listening on an IP address and port, one can send a packet with Content-Length: 0 and it crashes the server. Improper handling of the case when Content-Length is 0 allows a user (with access to the endpoint) to perform a remote Denial of service attack. The crash happens because of a NULL pointer dereference when 0 (from the Content-Length) is passed to the function cfl_sds_len, which in turn tries to cast a NULL pointer into struct cfl_sds. This is related to process_payload_traces_proto_ng() at opentelemetry_prot.c.","modified":"2026-04-21T04:36:50.453081Z","published":"2025-02-18T18:15:25Z","upstream":["CVE-2024-50609"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-50609"}],"affected":[{"package":{"name":"fluent-bit","ecosystem":"Azure Linux:2","purl":"pkg:rpm/azure-linux/fluent-bit"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.6-2"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-57086.json"}}],"schema_version":"1.7.5"}