---
id: CVE-2026-42306
title: >-
  github.com/docker/docker: github.com/moby/moby: Moby container framework: Host
  file overwrite via race condition in docker cp mount setup (…
summary: >-
  A flaw was found in the Moby container framework. A race condition occurs
  during the `docker cp` mount setup, which a malicious container can exploit.
  This vulnerability allows the container to redirect a bind mount target to an
  arbitrary …
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:H'
cvssSource: vendor
cwe: CWE-367
vendor: Red Hat
product: Red Hat Edge Manager 1.1
affected:
  - assisted_installer_for_red_hat_openshift_container_platform 2
  - confidential_compute_attestation
  - kernel_module_management_operator_for_red_hat_openshift
  - logging_subsystem_for_red_hat_openshift
  - logical_volume_manager_storage
  - machine_deletion_remediation_operator
  - migration_toolkit_for_containers
  - migration_toolkit_for_virtualization
  - multiarch_tuning_operator
  - multicluster_engine_for_kubernetes
  - node_healthcheck_operator
  - openshift_api_for_data_protection
  - openshift_developer_tools_and_services
  - openshift_lightspeed
  - openshift_serverless
  - openshift_service_mesh 2
  - openshift_service_mesh 3
  - power_monitoring_for_red_hat_openshift
  - advanced_cluster_security 4
  - ansible_automation_platform 2
  - build_of_kueue
  - ceph_storage 5
  - ceph_storage 6
  - ceph_storage 7
  - ceph_storage 8
  - ceph_storage 9
  - hardened_images
  - openshift_ai_rhoai
  - openshift_container_platform 4
  - openshift_data_foundation 4
  - openshift_gitops
  - openshift_virtualization 4
  - openstack_platform 16.2
  - openstack_platform 17.1
  - openstack_platform 18.0
  - quay 3
  - zero_trust_workload_identity_manager
  - zero_trust_workload_identity_manager_tech_preview
  - rhem_1_1_for_rhel 10
  - rhem_1_1_for_rhel 9
patched:
  - rhem_1_1_for_rhel 10
  - rhem_1_1_for_rhel 9
  - multicluster_global_hub 1.4.9
  - multicluster_global_hub 1.5.8
  - multicluster_global_hub 1.6.5
  - multicluster_global_hub 1.7.3
  - openshift_api_for_data_protection 1.3
  - openshift_api_for_data_protection 1.4
  - openshift_developer_tools_and_services 1.6.4
  - edge_manager 1.1
published: '2026-06-12'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T19:16:27+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42306.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42306.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-42306'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2488484'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-42306'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-42306'
  - url: 'https://github.com/moby/moby/security/advisories/GHSA-rg2x-37c3-w2rh'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68334'
  - url: 'https://access.redhat.com/errata/RHSA-2026:55810'
  - url: 'https://access.redhat.com/errata/RHSA-2026:54577'
  - url: 'https://access.redhat.com/errata/RHSA-2026:54392'
  - url: 'https://access.redhat.com/errata/RHSA-2026:53530'
  - url: 'https://access.redhat.com/errata/RHSA-2026:51033'
  - url: 'https://access.redhat.com/errata/RHSA-2026:59467'
  - url: 'https://access.redhat.com/errata/RHSA-2026:51057'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68044'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68253'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.001
epssPercentile: 0.00777
aliases:
  - GO-2026-5617
  - GHSA-rg2x-37c3-w2rh
ecosystem: go
ingestedAt: '2026-07-28T19:09:13.352Z'
---

## Overview

A flaw was found in the Moby container framework. A race condition occurs during the `docker cp` mount setup, which a malicious container can exploit. This vulnerability allows the container to redirect a bind mount target to an arbitrary path on the host system. Consequently, an attacker could overwrite host files, potentially leading to data corruption or a denial of service.

## Vendor advisories

- **RHSA-2026:68334** · Red Hat · fixed in: RHEM 1.1 for RHEL 10, RHEM 1.1 for RHEL 9 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68334)
- **RHSA-2026:55810** · Red Hat · fixed in: Multicluster Global Hub 1.4.9 · released 2026-08-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:55810)
- **RHSA-2026:54577** · Red Hat · fixed in: Multicluster Global Hub 1.5.8 · released 2026-08-13 · [advisory](https://access.redhat.com/errata/RHSA-2026:54577)
- **RHSA-2026:54392** · Red Hat · fixed in: Multicluster Global Hub 1.6.5 · released 2026-08-12 · [advisory](https://access.redhat.com/errata/RHSA-2026:54392)
- **RHSA-2026:53530** · Red Hat · fixed in: Multicluster Global Hub 1.7.3 · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53530)
- **RHSA-2026:51033** · Red Hat · fixed in: OpenShift API for Data Protection 1.3 · released 2026-08-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:51033)
- **RHSA-2026:59467** · Red Hat · fixed in: OpenShift API for Data Protection 1.4 · released 2026-08-25 · [advisory](https://access.redhat.com/errata/RHSA-2026:59467)
- **RHSA-2026:51057** · Red Hat · fixed in: OpenShift Developer Tools and Services 1.6.4 · released 2026-08-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:51057)
- **RHSA-2026:68044** · Red Hat · fixed in: Red Hat Edge Manager 1.1 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68044)
- **RHSA-2026:68253** · Red Hat · fixed in: Red Hat Edge Manager 1.1 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68253)
- **Red Hat VEX** · Important · affected: Assisted Installer for Red Hat OpenShift Container Platform 2, Confidential Compute Attestation, Kernel Module Management Operator for Red Hat Openshift, Logging Subsystem for Red Hat OpenShift, Logical Volume Manager Storage, Machine Deletion Remediation Operator, … · no fix planned: Confidential Compute Attestation, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42306.json)

**github.com/docker/docker: github.com/moby/moby: Moby container framework: Host file overwrite via race condition in docker cp mount setup** — rated Important by Red Hat. Released 2026-06-12, updated 2026-09-24.

Affected:

- Assisted Installer for Red Hat OpenShift Container Platform 2
- Confidential Compute Attestation
- Kernel Module Management Operator for Red Hat Openshift
- Logging Subsystem for Red Hat OpenShift
- Logical Volume Manager Storage
- Machine Deletion Remediation Operator
- Migration Toolkit for Containers
- Migration Toolkit for Virtualization
- Multiarch Tuning Operator
- Multicluster Engine for Kubernetes
- Node HealthCheck Operator
- OpenShift API for Data Protection
- OpenShift Developer Tools and Services
- OpenShift Lightspeed
- OpenShift Serverless
- OpenShift Service Mesh 2
- OpenShift Service Mesh 3
- Power monitoring for Red Hat OpenShift
- Red Hat Advanced Cluster Security 4
- Red Hat Ansible Automation Platform 2
- Red Hat Build of Kueue
- Red Hat Ceph Storage 5
- Red Hat Ceph Storage 6
- Red Hat Ceph Storage 7
- Red Hat Ceph Storage 8
- Red Hat Ceph Storage 9
- Red Hat Hardened Images
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat Openshift Data Foundation 4
- Red Hat OpenShift GitOps
- Red Hat OpenShift Virtualization 4
- Red Hat OpenStack Platform 16.2
- Red Hat OpenStack Platform 17.1
- Red Hat OpenStack Platform 18.0
- Red Hat Quay 3
- Zero Trust Workload Identity Manager
- Zero Trust Workload Identity Manager - Tech Preview

Fixed:

- RHEM 1.1 for RHEL 10
- RHEM 1.1 for RHEL 9
- Multicluster Global Hub 1.4.9
- Multicluster Global Hub 1.5.8
- Multicluster Global Hub 1.6.5
- Multicluster Global Hub 1.7.3
- OpenShift API for Data Protection 1.3
- OpenShift API for Data Protection 1.4
- OpenShift Developer Tools and Services 1.6.4
- Red Hat Edge Manager 1.1

No fix planned:

- Confidential Compute Attestation
- Red Hat Ansible Automation Platform 2
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Kernel Module Management Operator for Red Hat Openshift
- Logging Subsystem for Red Hat OpenShift
- Logical Volume Manager Storage
- Migration Toolkit for Containers
- Migration Toolkit for Virtualization
- Multiarch Tuning Operator
- OpenShift Developer Tools and Services
- OpenShift Lightspeed
- OpenShift Service Mesh 2
- OpenShift Service Mesh 3
- Red Hat Advanced Cluster Security 4
- Red Hat Build of Kueue
- Red Hat Ceph Storage 5
- Red Hat Ceph Storage 6
- Red Hat Ceph Storage 7
- Red Hat Ceph Storage 8
- Red Hat Ceph Storage 9
- Red Hat Openshift Data Foundation 4
- Red Hat OpenShift GitOps
- Red Hat OpenShift Virtualization 4
- Red Hat OpenStack Platform 16.2
- Red Hat OpenStack Platform 17.1
- Red Hat OpenStack Platform 18.0
- Red Hat Quay 3
- Zero Trust Workload Identity Manager
- Zero Trust Workload Identity Manager - Tech Preview
- Assisted Installer for Red Hat OpenShift Container Platform 2
- Machine Deletion Remediation Operator
- Multicluster Engine for Kubernetes
- Node HealthCheck Operator
- OpenShift API for Data Protection
- OpenShift Serverless
- Power monitoring for Red Hat OpenShift
- Red Hat Hardened Images

Not affected:

- RHEM 1.1 for RHEL 10
- RHEM 1.1 for RHEL 9
- Multicluster Global Hub 1.4.9
- Multicluster Global Hub 1.5.8
- Multicluster Global Hub 1.6.5
- Multicluster Global Hub 1.7.3
- OpenShift API for Data Protection 1.3
- OpenShift API for Data Protection 1.4
- Red Hat Edge Manager 1.1
- Gatekeeper 3

## Remediation

See the following documentation for details on how to enable Red Hat Edge
Manager and more:
https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.1 https://access.redhat.com/errata/RHSA-2026:68334
For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:

https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.13/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:55810
For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:

https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.14/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:54577

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

## Package advisory (CVE-2026-42306)

Affected packages:

- `github.com/docker/docker`
- `github.com/moby/moby`
- `github.com/moby/moby/v2 < 2.0.0-beta.14`

Patched in:

- `github.com/moby/moby/v2 2.0.0-beta.14`

Source: https://osv.dev/vulnerability/GO-2026-5617
