CVE-2021-21285

MEDIUM6.5EPSS 0.35%

moby docker daemon crash during image pull of malicious image

Published: 1/31/2024Modified: 3/13/2026
Also known as:GHSA-6fj5-m822-rqx8CGA-m4pv-q626-f9gm

Description

### Impact Pulling an intentionally malformed Docker image manifest crashes the `dockerd` daemon. ### Patches Versions 20.10.3 and 19.03.15 contain patches that prevent the daemon from crashing. ### Credits Maintainers would like to thank Josh Larsen, Ian Coldwater, Duffie Cooley, Rory McCune for working on the vulnerability and Brad Geesaman for responsibly disclosing it to [email protected].

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

References (10)