Bug 2493568

Summary: CVE-2026-41567 docker-compose: Moby/Docker Engine: Arbitrary Code Execution via malicious container image and compressed archive upload [fedora-all]
Product: [Fedora] Fedora Reporter: Isaiah Johnson <isjohnso>
Component: docker-composeAssignee: Maxwell G <maxwell>
Status: CLOSED NOTABUG QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: high Docs Contact:
Priority: high    
Version: rawhideCC: bradley.g.smith, error, go-sig, maxwell, ttomecek
Target Milestone: ---Keywords: Security, SecurityTracking
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: {"flaws": ["d8e890bd-d0c5-4c73-a511-cb21bae02d93"]}
Fixed In Version: Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2026-08-03 16:26:18 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2485356    

Description Isaiah Johnson 2026-06-26 15:04:56 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Comment 1 Brad Smith 2026-08-03 16:26:18 UTC
govulcheck reports that this vulnerability is found in a required module, but appears to not be called (#2 below).

=== Module Results ===

Vulnerability #1: GO-2026-5932
    The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design,
    and has known security issues
  More info: https://pkg.go.dev/vuln/GO-2026-5932
  Module: golang.org/x/crypto
    Found in: golang.org/x/crypto.0
    Fixed in: N/A

Vulnerability #2: GO-2026-5746
    Docker: 'PUT /containers/{id}/archive' executes container binary on the host
    in github.com/docker/docker
  More info: https://pkg.go.dev/vuln/GO-2026-5746
  Module: github.com/docker/docker
    Found in: github.com/docker/docker.2+incompatible
    Fixed in: N/A

Vulnerability #3: GO-2026-5617
    Race condition in 'docker cp' in github.com/docker/docker allows bind mount
    redirection
  More info: https://pkg.go.dev/vuln/GO-2026-5617
  Module: github.com/docker/docker
    Found in: github.com/docker/docker.2+incompatible
    Fixed in: N/A


This scan also found 0 vulnerabilities in packages you import and 3
vulnerabilities in modules you require, but your code doesn't appear to call
these vulnerabilities.