Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to redirect a bind mount target to an arbitrary host path, potentially overwriting host files or causing denial of service. This issue has been patched in Docker Engine version 29.5.1 and Moby Daemon version 2.0.0-beta.14.
CVSS Details
- CVSS 3.1 Base Score: 7.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade dockerUpgrade docker-debuginfo | Jun 9, 2026 | Jun 9, 2026 |
| Amazon_linux_2023 | — | Upgrade docker-debuginfoUpgrade dockerUpgrade docker-debugsource | Jun 15, 2026 | Jun 12, 2026 |
| Debian | — | Upgrade docker.io | Aug 17, 2026 | Aug 17, 2026 |
| Redhat_linux | — | Upgrade flightctl-cliUpgrade flightctl-agentUpgrade flightctl-servicesUpgrade flightctl-observabilityUpgrade flightctl-selinux | Sep 18, 2026 | Jun 12, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 6, 2026 | Jun 12, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub