Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41567

Опубликовано: 05 июн. 2026
Источник: redhat
CVSS3: 7.5

Описание

Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via PUT /containers/{id}/archive or piped through docker cp -, the daemon resolves decompression binaries (such as xz or unpigz) from the container's filesystem rather than the host's due to incorrect ordering of operations. A malicious container image containing a trojanized decompression binary can achieve arbitrary code execution with full daemon privileges, including host root UID and unrestricted capabilities, when a user uploads a compressed (xz or gzip) archive into that container. This issue is fixed in Docker Engine 29.5.1 and moby/moby v2.0.0-beta.14. Workarounds include only running containers from trusted images, using authorization plugins to restrict access to the PUT /containers/{id}/archive endpoint, and avoiding piping compressed archives into containers created from untrusted images

A flaw was found in Moby, the open-source container framework, and Docker Engine. A malicious container image can exploit this vulnerability to achieve arbitrary code execution with full daemon privileges, including host root access. This occurs when a user uploads a compressed archive to the container, as the daemon incorrectly uses decompression binaries from the container's filesystem. This allows an attacker to gain complete control over the affected system.

Отчет

This is an Important vulnerability. A flaw in Moby and Docker Engine allows for arbitrary code execution with host root privileges. This occurs when a user uploads a compressed archive to a container, as the daemon incorrectly uses decompression binaries from the container's filesystem. This could lead to a complete compromise of the host system if a malicious container image is utilized.

Меры по смягчению последствий

To mitigate this issue, Red Hat recommends only running containers from trusted images. Additionally, users should avoid piping compressed archives into containers created from untrusted images. For environments utilizing authorization plugins, restricting access to the PUT /containers/{id}/archive endpoint can further reduce exposure.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/agent-client-rhel9Affected
Multicluster Engine for Kubernetesmulticluster-engine/assisted-service-8-rhel8Affected
Multicluster Engine for Kubernetesmulticluster-engine/assisted-service-9-rhel9Affected
Multicluster Engine for Kubernetesmulticluster-engine/cluster-api-provider-azure-rhel9Affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-rhel9-operatorAffected
OpenShift Source-to-Image (S2I)source-to-image/source-to-image-rhel8Affected
OpenShift Source-to-Image (S2I)source-to-image/source-to-image-rhel9Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel9Not affected
Red Hat Ceph Storage 5rhceph/rhceph-5-dashboard-rhel8Fix deferred
Red Hat Ceph Storage 7rhceph/grafana-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-427
https://bugzilla.redhat.com/show_bug.cgi?id=2485356docker: Moby/Docker Engine: Arbitrary Code Execution via malicious container image and compressed archive upload

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.2
ubuntu
около 2 месяцев назад

Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the container's filesystem rather than the host's due to incorrect ordering of operations. A malicious container image containing a trojanized decompression binary can achieve arbitrary code execution with full daemon privileges, including host root UID and unrestricted capabilities, when a user uploads a compressed (xz or gzip) archive into that container. This issue is fixed in Docker Engine 29.5.1 and moby/moby v2.0.0-beta.14. Workarounds include only running containers from trusted images, using authorization plugins to restrict access to the `PUT /containers/{id}/archive` endpoint, and avoiding piping compressed archives into containers created from untrusted images

CVSS3: 7.2
nvd
около 2 месяцев назад

Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the container's filesystem rather than the host's due to incorrect ordering of operations. A malicious container image containing a trojanized decompression binary can achieve arbitrary code execution with full daemon privileges, including host root UID and unrestricted capabilities, when a user uploads a compressed (xz or gzip) archive into that container. This issue is fixed in Docker Engine 29.5.1 and moby/moby v2.0.0-beta.14. Workarounds include only running containers from trusted images, using authorization plugins to restrict access to the `PUT /containers/{id}/archive` endpoint, and avoiding piping compressed archives into containers created from untrusted images

CVSS3: 7.2
debian
около 2 месяцев назад

Moby is an open source container framework. In versions prior to 29.5. ...

CVSS3: 7.2
redos
около 1 месяца назад

Уязвимость docker-ce

CVSS3: 7.2
github
3 месяца назад

Docker: `PUT /containers/{id}/archive` executes container binary on the host

7.5 High

CVSS3

Уязвимость CVE-2026-41567