Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41568

Опубликовано: 12 июн. 2026
Источник: redhat
CVSS3: 3.9
EPSS Низкий

Описание

Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to create empty files or directories at arbitrary absolute paths on the host filesystem. This issue has been patched in Docker Engine version 29.5.1 and Moby Daemon version 2.0.0-beta.14.

A flaw was found in the Moby container framework. A race condition during the docker cp mount setup allows a malicious container to create empty files or directories at arbitrary locations on the host filesystem. This vulnerability can lead to a denial of service by filling up disk space or interfering with critical system files.

Отчет

This flaw is rated as Low impact. A race condition in the docker cp mount setup within the Moby container framework allows a malicious container to create empty files or directories at arbitrary locations on the host filesystem. Successful exploitation is difficult (AC:H) due to the timing-dependent nature of the race condition. Containers that do not have volume mounts are not affected, as the race occurs during volume bind-mount setup. Denial of Service is possible by:

  • Converting /etc/docker/daemon.json into a directory prevents the daemon from restarting
  • Creating /etc/nologin prevents user logins
  • Overwriting critical system paths with empty files can break host services The container does not gain read or write access to existing host files — only the ability to create new empty files or directories at chosen paths.

Меры по смягчению последствий

Avoid using docker cp with untrusted running containers. Recommended to apply patches: Mountpoint creation is now scoped to the container root using os.Root (Go 1.24+), which refuses to follow symlinks that escape the opened root directory. All filesystem operations in createIfNotExists (MkdirAll, OpenFile) are performed through the os.Root handle, so even if a symlink swap occurs after path resolution, the creation stays confined to the container root.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2assisted/agent-preinstall-image-builder-rhel9Under investigation
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-agent-rhel9Under investigation
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-controller-rhel9Under investigation
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-rhel9Under investigation
Confidential Compute Attestationopenshift-sandboxed-containers/osc-cloud-api-adaptor-rhel9Under investigation
Confidential Compute Attestationopenshift-sandboxed-containers/osc-must-gather-rhel9Under investigation
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Under investigation
Confidential Compute Attestationopenshift-sandboxed-containers/osc-rhel9-operatorUnder investigation
Gatekeeper 3gatekeeper/gatekeeper-rhel9Under investigation
Kernel Module Management Operator for Red Hat Openshiftkmm/kernel-module-management-must-gather-rhel9Under investigation

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-367
https://bugzilla.redhat.com/show_bug.cgi?id=2488493github.com/docker/docker: github.com/moby/moby: Moby: Denial of Service via race condition in docker cp mount setup

EPSS

Процентиль: 1%
0.00108
Низкий

3.9 Low

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 2 месяцев назад

Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to create empty files or directories at arbitrary absolute paths on the host filesystem. This issue has been patched in Docker Engine version 29.5.1 and Moby Daemon version 2.0.0-beta.14.

CVSS3: 6.1
nvd
около 2 месяцев назад

Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to create empty files or directories at arbitrary absolute paths on the host filesystem. This issue has been patched in Docker Engine version 29.5.1 and Moby Daemon version 2.0.0-beta.14.

CVSS3: 6.1
debian
около 2 месяцев назад

Moby is an open source container framework. In Docker Engine prior to ...

CVSS3: 6.1
redos
около 1 месяца назад

Уязвимость docker-ce

CVSS3: 6.1
github
3 месяца назад

Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap

EPSS

Процентиль: 1%
0.00108
Низкий

3.9 Low

CVSS3