MEDIUM6.5
GHSA-6fj5-m822-rqx8
moby docker daemon crash during image pull of malicious image
Quick fix
GHSA-6fj5-m822-rqx8 — github.com/moby/moby: upgrade to the fixed version with the command below.
go get github.com/moby/moby@v19.3.15Details
### Impact
Pulling an intentionally malformed Docker image manifest crashes the `dockerd` daemon.
### Patches
Versions 20.10.3 and 19.03.15 contain patches that prevent the daemon from crashing.
### Credits
Maintainers would like to thank Josh Larsen, Ian Coldwater, Duffie Cooley, Rory McCune for working on the vulnerability and Brad Geesaman for responsibly disclosing it to security@docker.com.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/moby/moby
Introduced in:
20.10.0-beta1Fixed in: 20.10.3Fix
go get github.com/moby/moby@v20.10.3References
- https://github.com/moby/moby/security/advisories/GHSA-6fj5-m822-rqx8[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2021-21285[ADVISORY]
- https://github.com/moby/moby/commit/8d3179546e79065adefa67cc697c09d0ab137d30[WEB]
- https://docs.docker.com/engine/release-notes/#20103[WEB]
- https://github.com/moby/moby/releases/tag/v19.03.15[WEB]
- https://github.com/moby/moby/releases/tag/v20.10.3[WEB]
- https://security.gentoo.org/glsa/202107-23[WEB]
- https://security.netapp.com/advisory/ntap-20210226-0005[WEB]
- https://www.debian.org/security/2021/dsa-4865[WEB]