Bug 2488484 (CVE-2026-42306) - CVE-2026-42306 github.com/docker/docker: github.com/moby/moby: Moby container framework: Host file overwrite via race condition in docker cp mount setup
Summary: CVE-2026-42306 github.com/docker/docker: github.com/moby/moby: Moby container...
Keywords:
Status: NEW
Alias: CVE-2026-42306
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2507672 2507673 2507674 2507675 2507676 2507677 2507678 2507679 2507681 2507682 2507683 2507686 2507687 2507688 2507690 2507691 2507692 2507693 2507694 2507695 2507696 2507697 2507698 2507699 2507700 2507701 2507702 2507703 2507704 2507705 2507706 2507707 2507709 2507710 2507712 2507713 2507680 2507684 2507685 2507689 2507708 2507711
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-12 19:01 UTC by OSIDB Bzimport
Modified: 2026-07-29 14:48 UTC (History)
118 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-06-12 19:01:33 UTC
Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to redirect a bind mount target to an arbitrary host path, potentially overwriting host files or causing denial of service. This issue has been patched in Docker Engine version 29.5.1 and Moby Daemon version 2.0.0-beta.14.


Note You need to log in before you can comment on or make changes to this bug.