CVE-2021-21285

MEDIUM6.5EPSS 0.35%

moby docker daemon crash during image pull of malicious image

發布日:2024/1/31修改日:2026/3/13
也稱為:GHSA-6fj5-m822-rqx8CGA-m4pv-q626-f9gm

描述

### Impact Pulling an intentionally malformed Docker image manifest crashes the `dockerd` daemon. ### Patches Versions 20.10.3 and 19.03.15 contain patches that prevent the daemon from crashing. ### Credits Maintainers would like to thank Josh Larsen, Ian Coldwater, Duffie Cooley, Rory McCune for working on the vulnerability and Brad Geesaman for responsibly disclosing it to [email protected].

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

參考連結(10)