Overview
About vulnerability
Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container viaPUT /containers/{id}/archive or piped through docker cp -, the daemon resolves decompression binaries (such as xz or unpigz) from the container’s filesystem rather than the host’s due to incorrect ordering of operations. A malicious container image containing a trojanized decompression binary can achieve arbitrary code execution with full daemon privileges, including host root UID and unrestricted capabilities, when a user uploads a compressed (xz or gzip) archive into that container. This issue is fixed in Docker Engine 29.5.1 and moby/moby v2.0.0-beta.14. Workarounds include only running containers from trusted images, using authorization plugins to restrict access to the PUT /containers/{id}/archive endpoint, and avoiding piping compressed archives into containers created from untrusted images
Details
- Affected product:
- Grafana , Loki , MinIO , cortexproject/cortex , dhui/dktest , drone-runners/drone-runner-docker , golang-migrate/migrate , google/go-cloud , grafana/e2e , grafana/grafana/pkg/promlib , grafana/grafana/pkg/storage/unified/apistore , grafana/grafana/pkg/storage/unified/resource , grafana/tempo , harness/drone-cli , influxdata/telegraf , m3dbx/prometheus_remote_client_golang , moby/moby/docker , open-telemetry/opentelemetry-collector , openfga/openfga , ory/fosite , ory/x , prometheus/prom2json , prometheus/prometheus , thanos-io/thanos
- Affected packages:
- github.com/docker/docker @ 26.0.2+incompatible (+53 more)