ALT-PU-2021-4842-1
Package docker-engine updated to version 20.10.3-alt1 for branch sisyphus in task 266041.
Closed vulnerabilities
BDU:2021-01892
Уязвимость демона dockerd средства автоматизации развёртывания и управления приложениями в средах с поддержкой контейнеризации Docker, связанная с ошибкой механизма контроля расходуемых ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-01893
Уязвимость опции --userns-remap средства автоматизации развёртывания и управления приложениями в средах с поддержкой контейнеризации Docker, связанная с некорректным ограничением имени пути к каталогу, позволяющая нарушителю оказать воздействие на целостность данных
Modified: 2024-11-21
CVE-2021-21284
In Docker before versions 9.03.15, 20.10.3 there is a vulnerability involving the --userns-remap option in which access to remapped root allows privilege escalation to real root. When using "--userns-remap", if the root user in the remapped namespace has access to the host filesystem they can modify files under "/var/lib/docker/
- https://docs.docker.com/engine/release-notes/#20103
- https://docs.docker.com/engine/release-notes/#20103
- https://github.com/moby/moby/commit/64bd4485b3a66a597c02c95f5776395e540b2c7c
- https://github.com/moby/moby/commit/64bd4485b3a66a597c02c95f5776395e540b2c7c
- https://github.com/moby/moby/releases/tag/v19.03.15
- https://github.com/moby/moby/releases/tag/v19.03.15
- https://github.com/moby/moby/releases/tag/v20.10.3
- https://github.com/moby/moby/releases/tag/v20.10.3
- https://github.com/moby/moby/security/advisories/GHSA-7452-xqpj-6rpc
- https://github.com/moby/moby/security/advisories/GHSA-7452-xqpj-6rpc
- GLSA-202107-23
- GLSA-202107-23
- https://security.netapp.com/advisory/ntap-20210226-0005/
- https://security.netapp.com/advisory/ntap-20210226-0005/
- DSA-4865
- DSA-4865
Modified: 2024-11-21
CVE-2021-21285
In Docker before versions 9.03.15, 20.10.3 there is a vulnerability in which pulling an intentionally malformed Docker image manifest crashes the dockerd daemon. Versions 20.10.3 and 19.03.15 contain patches that prevent the daemon from crashing.
- https://docs.docker.com/engine/release-notes/#20103
- https://docs.docker.com/engine/release-notes/#20103
- https://github.com/moby/moby/commit/8d3179546e79065adefa67cc697c09d0ab137d30
- https://github.com/moby/moby/commit/8d3179546e79065adefa67cc697c09d0ab137d30
- https://github.com/moby/moby/releases/tag/v19.03.15
- https://github.com/moby/moby/releases/tag/v19.03.15
- https://github.com/moby/moby/releases/tag/v20.10.3
- https://github.com/moby/moby/releases/tag/v20.10.3
- https://github.com/moby/moby/security/advisories/GHSA-6fj5-m822-rqx8
- https://github.com/moby/moby/security/advisories/GHSA-6fj5-m822-rqx8
- GLSA-202107-23
- GLSA-202107-23
- https://security.netapp.com/advisory/ntap-20210226-0005/
- https://security.netapp.com/advisory/ntap-20210226-0005/
- DSA-4865
- DSA-4865