Bug 2488484 (CVE-2026-42306)

Summary: CVE-2026-42306 github.com/docker/docker: github.com/moby/moby: Moby container framework: Host file overwrite via race condition in docker cp mount setup
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: adudiak, agarcial, alcohan, amctagga, anjoseph, anpicker, aoconnor, aruklets, asatyam, asegurap, bdettelb, bniver, cahl, cdrage, crizzo, derez, dfreiber, dhanak, diagrawa, dkeler, doconnor, drosa, drow, dschmidt, dsimansk, dymurray, eborisov, eglynn, erezende, fdeutsch, flucifre, gmeno, gparvin, groman, hasun, ibolton, jbalunas, jburrell, jcantril, jfula, jjoyce, jkoehler, jlanda, jmatthew, jmitchel, jmontleo, jowilson, jprabhak, jpretori, jsamir, jschluet, kaycoth, kbempah, kingland, kshier, lball, lchilton, lgamliel, lhh, ljawale, lphiri, luizcosta, lwan, manissin, mbenjamin, mburns, mgarciac, mhackett, mnovotny, msilmser, ngough, nweather, nyancey, ometelka, oramraz, pahickey, pakotvan, pgaikwad, ptisnovs, rbobbitt, rekumar, rfreiman, rhaigner, rhel-process-autobot, rjohnson, rojacob, rushinde, sabiswas, sakbas, sausingh, sbratsla, sdawley, sfeifer, simaishi, slucidi, smcdonal, smullick, solenoci, sostapov, sseago, stcannon, sthirugn, stirabos, suppawar, syedriko, teagle, thason, tzivkovi, vereddy, veshanka, vkumar, vvoronko, watson-tool-maintainers, whayutin, wtam, xdharmai, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the Moby container framework. A race condition occurs during the `docker cp` mount setup, which a malicious container can exploit. This vulnerability allows the container to redirect a bind mount target to an arbitrary path on the host system. Consequently, an attacker could overwrite host files, potentially leading to data corruption or a denial of service.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2507672, 2507673, 2507674, 2507677, 2507678, 2507681, 2507682, 2507683, 2507686, 2507687, 2507688, 2507691, 2507692, 2507693, 2507694, 2507695, 2507697, 2507698, 2507701, 2507702, 2507703, 2507704, 2507705, 2507706, 2507709, 2507710, 2507712, 2507713, 2507675, 2507676, 2507679, 2507680, 2507684, 2507685, 2507689, 2507690, 2507696, 2507699, 2507700, 2507707, 2507708, 2507711    
Bug Blocks:    

Description OSIDB Bzimport 2026-06-12 19:01:33 UTC
Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to redirect a bind mount target to an arbitrary host path, potentially overwriting host files or causing denial of service. This issue has been patched in Docker Engine version 29.5.1 and Moby Daemon version 2.0.0-beta.14.