CVE-2021-21284Medium· 6.8▾ Sunlitmoby Access to remapped root allows privilege escalation to real root
▾ Sunlit zone — Low / medium · no exploitation signal
impact 37.4 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
1.1%
Last analysed / modified upstream
When using --userns-remap, if the root user in the remapped namespace has access to the host filesystem they can modify files under /var/lib/docker/<remapping> that cause writing files with extended privileges.
Versions 20.10.3 and 19.03.15 contain patches that prevent privilege escalation from remapped user.
Maintainers would like to thank Alex Chapman for discovering the vulnerability; @awprice, @nathanburrell, @raulgomis, @chris-walz, @erin-jensby, @bassmatt, @mark-adams, @dbaxa for working on it and Zac Ellis for responsibly disclosing it to [email protected]
github.com/moby/moby < 19.3.15github.com/moby/moby >= 20.10.0-beta1, < 20.10.3Upgrade to a patched release:
github.com/moby/moby 19.3.15github.com/moby/moby 20.10.3Connected by shared product, vendor, weakness, or advisory.
CVE-2021-21285Medium· 6.5moby docker daemon crash during image pull of malicious image
CVE-2020-27534Medium· 5.3Path Traversal in Moby builder
CVE-2022-24769Medium· 5.9Moby (Docker Engine) started with non-empty inheritable Linux process capabilities
CVE-2024-36621Medium· 6.5Moby Race Condition vulnerability
CVE-2021-41091Medium· 5.9Moby (Docker Engine) Insufficiently restricted permissions on data directory
CVE-2026-33748High· 7.5BuildKit Git URL subdir component can cause access to restricted files