Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-09696

Опубликовано: 18 мая 2026
Источник: fstec
CVSS3: 7.2
CVSS2: 5.5
EPSS Низкий

Описание

Уязвимость программного средства для создания систем контейнерной изоляции Moby связана с неконтролируемым элементом пути поиска при распаковке сжатых архивов xz или gzip. Эксплуатация уязвимости может позволить нарушителю повысить свои привилегии и выполнить произвольный код

Вендор

ООО «Ред Софт»
Red Hat Inc.
Moby Project

Наименование ПО

РЕД ОС
Red Hat Advanced Cluster Management for Kubernetes
Red Hat OpenShift Container Platform
Red Hat Enterprise Linux
Red Hat Ceph Storage
multicluster engine for Kubernetes
Red Hat OpenShift Lightspeed
Red Hat OpenShift distributed tracing
Red Hat Hardened Images
OpenShift Source-to-Image
Exploit Intelligence
Moby

Версия ПО

7.3 (РЕД ОС)
2 (Red Hat Advanced Cluster Management for Kubernetes)
4 (Red Hat OpenShift Container Platform)
9 (Red Hat Enterprise Linux)
5 (Red Hat Ceph Storage)
- (multicluster engine for Kubernetes)
7 (Red Hat Ceph Storage)
8 (Red Hat Ceph Storage)
- (Red Hat OpenShift Lightspeed)
10 (Red Hat Enterprise Linux)
8.0 (РЕД ОС)
9 (Red Hat Ceph Storage)
3 (Red Hat OpenShift distributed tracing)
- (Red Hat Hardened Images)
- (OpenShift Source-to-Image)
- (Exploit Intelligence)
до 29.5.1 (Moby)

Тип ПО

Операционная система
Сетевое средство
Прикладное ПО информационных систем

Операционные системы и аппаратные платформы

ООО «Ред Софт» РЕД ОС 7.3
Red Hat Inc. Red Hat Enterprise Linux 9
Red Hat Inc. Red Hat Enterprise Linux 10
ООО «Ред Софт» РЕД ОС 8.0

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 5,5)
Высокий уровень опасности (базовая оценка CVSS 3.1 составляет 7,2)

Возможные меры по устранению уязвимости

Использование рекомендаций производителя:
Для Moby:
https://github.com/moby/moby/releases#release-docker-v29.5.1
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2026-41567
Для РедОС:
https://redos.red-soft.ru/search/?iblock_id=&q=CVE-2026-41567

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 5%
0.00153
Низкий

7.2 High

CVSS3

5.5 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.2
ubuntu
около 2 месяцев назад

Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the container's filesystem rather than the host's due to incorrect ordering of operations. A malicious container image containing a trojanized decompression binary can achieve arbitrary code execution with full daemon privileges, including host root UID and unrestricted capabilities, when a user uploads a compressed (xz or gzip) archive into that container. This issue is fixed in Docker Engine 29.5.1 and moby/moby v2.0.0-beta.14. Workarounds include only running containers from trusted images, using authorization plugins to restrict access to the `PUT /containers/{id}/archive` endpoint, and avoiding piping compressed archives into containers created from untrusted images

CVSS3: 7.5
redhat
около 2 месяцев назад

Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the container's filesystem rather than the host's due to incorrect ordering of operations. A malicious container image containing a trojanized decompression binary can achieve arbitrary code execution with full daemon privileges, including host root UID and unrestricted capabilities, when a user uploads a compressed (xz or gzip) archive into that container. This issue is fixed in Docker Engine 29.5.1 and moby/moby v2.0.0-beta.14. Workarounds include only running containers from trusted images, using authorization plugins to restrict access to the `PUT /containers/{id}/archive` endpoint, and avoiding piping compressed archives into containers created from untrusted images

CVSS3: 7.2
nvd
около 2 месяцев назад

Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the container's filesystem rather than the host's due to incorrect ordering of operations. A malicious container image containing a trojanized decompression binary can achieve arbitrary code execution with full daemon privileges, including host root UID and unrestricted capabilities, when a user uploads a compressed (xz or gzip) archive into that container. This issue is fixed in Docker Engine 29.5.1 and moby/moby v2.0.0-beta.14. Workarounds include only running containers from trusted images, using authorization plugins to restrict access to the `PUT /containers/{id}/archive` endpoint, and avoiding piping compressed archives into containers created from untrusted images

CVSS3: 7.2
debian
около 2 месяцев назад

Moby is an open source container framework. In versions prior to 29.5. ...

CVSS3: 7.2
redos
около 1 месяца назад

Уязвимость docker-ce

EPSS

Процентиль: 5%
0.00153
Низкий

7.2 High

CVSS3

5.5 Medium

CVSS2