GHSA-hfg8-hc9c-6c3h
moby/go-archive: Crafted tar archive can write outside the extraction directory
Quick fix
GHSA-hfg8-hc9c-6c3h — github.com/moby/go-archive: upgrade to the fixed version with the command below.
go get github.com/moby/go-archive@v0.3.0 Details
### Summary The tar extraction routines in `moby/go-archive` (`Unpack`, `UnpackLayer`, `Untar`/`UntarUncompressed`, and the `ApplyLayer` helpers) do not confine filesystem operations to the destination directory. A crafted archive can create or overwrite files **outside** the intended destination.
### Details The extractor decides where each archive entry lands using lexical string checks and then performs the filesystem operation on a path that is resolved by the OS, so a links introduced by the archive can be followed out of the destination directory.
### Impact An attacker who controls the contents of archive can create or overwrite files at arbitrary paths writable by the extracting process.
### Workarounds Only extract trusted archives.
Are you affected?
Enter the version of the package you're using.
Affected packages
0 Fixed in: 0.3.0 go get github.com/moby/go-archive@v0.3.0 References
- https://github.com/moby/go-archive/security/advisories/GHSA-hfg8-hc9c-6c3h [WEB]
- https://github.com/moby/moby/issues/52948 [WEB]
- https://docs.docker.com/desktop/release-notes/#4860 [WEB]
- https://github.com/bikini/exploitarium/tree/main/docker-cp-copyout-destination-escape [WEB]
- https://github.com/docker/cli/releases/tag/v29.7.0 [WEB]
- https://github.com/moby/go-archive [PACKAGE]
- https://github.com/moby/moby/releases/tag/docker-v29.7.0 [WEB]
- https://www.imperva.com/blog/copyescape-taking-over-docker-hosts-with-docker-cp [WEB]