CVE-2021-21285Medium· 6.5▾ Sunlitmoby docker daemon crash during image pull of malicious image
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.7 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
3.3%
Last analysed / modified upstream
Pulling an intentionally malformed Docker image manifest crashes the dockerd daemon.
Versions 20.10.3 and 19.03.15 contain patches that prevent the daemon from crashing.
Maintainers would like to thank Josh Larsen, Ian Coldwater, Duffie Cooley, Rory McCune for working on the vulnerability and Brad Geesaman for responsibly disclosing it to [email protected].
github.com/moby/moby < 19.3.15github.com/moby/moby >= 20.10.0-beta1, < 20.10.3Upgrade to a patched release:
github.com/moby/moby 19.3.15github.com/moby/moby 20.10.3Connected by shared product, vendor, weakness, or advisory.
CVE-2021-21284Medium· 6.8moby Access to remapped root allows privilege escalation to real root
CVE-2020-27534Medium· 5.3Path Traversal in Moby builder
CVE-2022-24769Medium· 5.9Moby (Docker Engine) started with non-empty inheritable Linux process capabilities
CVE-2024-36621Medium· 6.5Moby Race Condition vulnerability
CVE-2021-41091Medium· 5.9Moby (Docker Engine) Insufficiently restricted permissions on data directory
CVE-2026-33748High· 7.5BuildKit Git URL subdir component can cause access to restricted files