Overview
A flaw was found in the Moby container framework. A race condition occurs during the docker cp mount setup, which a malicious container can exploit. This vulnerability allows the container to redirect a bind mount target to an arbitrary path on the host system. Consequently, an attacker could overwrite host files, potentially leading to data corruption or a denial of service.
Vendor advisories
- RHSA-2026:68334 · Red Hat · fixed in: RHEM 1.1 for RHEL 10, RHEM 1.1 for RHEL 9 · released 2026-09-16 · advisory
- RHSA-2026:55810 · Red Hat · fixed in: Multicluster Global Hub 1.4.9 · released 2026-08-17 · advisory
- RHSA-2026:54392 · Red Hat · fixed in: Multicluster Global Hub 1.6.5 · released 2026-08-12 · advisory
- RHSA-2026:53530 · Red Hat · fixed in: Multicluster Global Hub 1.7.3 · released 2026-08-11 · advisory
- RHSA-2026:51033 · Red Hat · fixed in: OpenShift API for Data Protection 1.3 · released 2026-08-06 · advisory
- RHSA-2026:59467 · Red Hat · fixed in: OpenShift API for Data Protection 1.4 · released 2026-08-25 · advisory
- RHSA-2026:51057 · Red Hat · fixed in: OpenShift Developer Tools and Services 1.6.3 · released 2026-08-06 · advisory
- RHSA-2026:68044 · Red Hat · fixed in: Red Hat Edge Manager 1.1 · released 2026-09-16 · advisory
- RHSA-2026:68253 · Red Hat · fixed in: Red Hat Edge Manager 1.1 · released 2026-09-16 · advisory
- RHSA-2026:54577 · Red Hat · fixed in: Red Hat multicluster global hub 1.5.3 · released 2026-08-13 · advisory
- Red Hat VEX · Important · affected: Assisted Installer for Red Hat OpenShift Container Platform 2, Confidential Compute Attestation, Kernel Module Management Operator for Red Hat Openshift, Logging Subsystem for Red Hat OpenShift, Logical Volume Manager Storage, Machine Deletion Remediation Operator, … · no fix planned: Confidential Compute Attestation, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, … · updated 2026-09-21 · vex
github.com/docker/docker: github.com/moby/moby: Moby container framework: Host file overwrite via race condition in docker cp mount setup — rated Important by Red Hat. Released 2026-06-12, updated 2026-09-21.
Affected:
- Assisted Installer for Red Hat OpenShift Container Platform 2
- Confidential Compute Attestation
- Kernel Module Management Operator for Red Hat Openshift
- Logging Subsystem for Red Hat OpenShift
- Logical Volume Manager Storage
- Machine Deletion Remediation Operator
- Migration Toolkit for Containers
- Migration Toolkit for Virtualization
- Multiarch Tuning Operator
- Multicluster Engine for Kubernetes
- Node HealthCheck Operator
- OpenShift API for Data Protection
- OpenShift Developer Tools and Services
- OpenShift Lightspeed
- OpenShift Serverless
- OpenShift Service Mesh 2
- OpenShift Service Mesh 3
- Power monitoring for Red Hat OpenShift
- Red Hat Advanced Cluster Security 4
- Red Hat Ansible Automation Platform 2
- Red Hat Build of Kueue
- Red Hat Ceph Storage 5
- Red Hat Ceph Storage 6
- Red Hat Ceph Storage 7
- Red Hat Ceph Storage 8
- Red Hat Ceph Storage 9
- Red Hat Hardened Images
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat Openshift Data Foundation 4
- Red Hat OpenShift GitOps
- Red Hat OpenShift Virtualization 4
- Red Hat OpenStack Platform 16.2
- Red Hat OpenStack Platform 17.1
- Red Hat OpenStack Platform 18.0
- Red Hat Quay 3
- Zero Trust Workload Identity Manager
- Zero Trust Workload Identity Manager - Tech Preview
Fixed:
- RHEM 1.1 for RHEL 10
- RHEM 1.1 for RHEL 9
- Multicluster Global Hub 1.4.9
- Multicluster Global Hub 1.6.5
- Multicluster Global Hub 1.7.3
- OpenShift API for Data Protection 1.3
- OpenShift API for Data Protection 1.4
- OpenShift Developer Tools and Services 1.6.3
- Red Hat Edge Manager 1.1
- Red Hat multicluster global hub 1.5.3
No fix planned:
- Confidential Compute Attestation
- Red Hat Ansible Automation Platform 2
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Kernel Module Management Operator for Red Hat Openshift
- Logging Subsystem for Red Hat OpenShift
- Logical Volume Manager Storage
- Migration Toolkit for Containers
- Migration Toolkit for Virtualization
- Multiarch Tuning Operator
- OpenShift Developer Tools and Services
- OpenShift Lightspeed
- OpenShift Service Mesh 2
- OpenShift Service Mesh 3
- Red Hat Advanced Cluster Security 4
- Red Hat Build of Kueue
- Red Hat Ceph Storage 5
- Red Hat Ceph Storage 6
- Red Hat Ceph Storage 7
- Red Hat Ceph Storage 8
- Red Hat Ceph Storage 9
- Red Hat Openshift Data Foundation 4
- Red Hat OpenShift GitOps
- Red Hat OpenShift Virtualization 4
- Red Hat OpenStack Platform 16.2
- Red Hat OpenStack Platform 17.1
- Red Hat OpenStack Platform 18.0
- Red Hat Quay 3
- Zero Trust Workload Identity Manager
- Zero Trust Workload Identity Manager - Tech Preview
- Assisted Installer for Red Hat OpenShift Container Platform 2
- Machine Deletion Remediation Operator
- Multicluster Engine for Kubernetes
- Node HealthCheck Operator
- OpenShift API for Data Protection
- OpenShift Serverless
- Power monitoring for Red Hat OpenShift
- Red Hat Hardened Images
Not affected:
- RHEM 1.1 for RHEL 10
- RHEM 1.1 for RHEL 9
- Multicluster Global Hub 1.4.9
- Multicluster Global Hub 1.6.5
- Multicluster Global Hub 1.7.3
- OpenShift API for Data Protection 1.3
- OpenShift API for Data Protection 1.4
- Red Hat Edge Manager 1.1
- Red Hat multicluster global hub 1.5.3
- Gatekeeper 3
Remediation
See the following documentation for details on how to enable Red Hat Edge
Manager and more:
https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.1 https://access.redhat.com/errata/RHSA-2026:68334
For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:
https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.13/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:55810
For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:
https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.15/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:54392
Workarounds / mitigations:
- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Package advisory (CVE-2026-42306)
Affected packages:
github.com/docker/docker
github.com/moby/moby
github.com/moby/moby/v2 < 2.0.0-beta.14
Patched in:
github.com/moby/moby/v2 2.0.0-beta.14
Source: https://osv.dev/vulnerability/GO-2026-5617