moby docker daemon crash during image pull of malicious image
Package
Affected versions
< 19.3.15
>= 20.10.0-beta1, < 20.10.3
Patched versions
19.3.15
20.10.3
Description
Published by the National Vulnerability Database
Feb 2, 2021
Published to the GitHub Advisory Database
Jan 31, 2024
Reviewed
Jan 31, 2024
Last updated
Jun 10, 2024
Impact
Pulling an intentionally malformed Docker image manifest crashes the
dockerd
daemon.Patches
Versions 20.10.3 and 19.03.15 contain patches that prevent the daemon from crashing.
Credits
Maintainers would like to thank Josh Larsen, Ian Coldwater, Duffie Cooley, Rory McCune for working on the vulnerability and Brad Geesaman for responsibly disclosing it to [email protected].
References