OESA-2026-3945

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-3945
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-3945.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2026-3945
Upstream
CVE (2)
Published
2026-09-20T13:23:28Z
Modified
2026-09-20T13:30:15Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:H CVSS Calculator
Summary
docker security update
Details

Security Fix(es):

Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to create empty files or directories at arbitrary absolute paths on the host filesystem. This issue has been patched in Docker Engine version 29.5.1 and Moby Daemon version 2.0.0-beta.14.(CVE-2026-41568)

Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to redirect a bind mount target to an arbitrary host path, potentially overwriting host files or causing denial of service. This issue has been patched in Docker Engine version 29.5.1 and Moby Daemon version 2.0.0-beta.14.(CVE-2026-42306)

Database specific
{
    "severity":  "High"
}
References

Affected packages

openEuler:20.03-LTS-SP4 / docker

Package

Name
docker
Purl
pkg:rpm/openEuler/docker&distro=openEuler-20.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
engine-18.09.0-279.oe2003sp4

Ecosystem specific

{
    "aarch64":  [
        "docker-engine-18.09.0-279.oe2003sp4.aarch64.rpm"
    ],
    "src":  [
        "docker-engine-18.09.0-279.oe2003sp4.src.rpm"
    ],
    "x86_64":  [
        "docker-engine-18.09.0-279.oe2003sp4.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-3945.json"