In Docker before versions 9.03.15, 20.10.3 there is a vulnerability in which pulling an intentionally malformed Docker image manifest crashes the dockerd daemon. Versions 20.10.3 and 19.03.15 contain patches that prevent the daemon from crashing.
References
Configurations
History
21 Nov 2024, 05:47
Type | Values Removed | Values Added |
---|---|---|
References | () https://docs.docker.com/engine/release-notes/#20103 - Release Notes, Vendor Advisory | |
References | () https://github.com/moby/moby/commit/8d3179546e79065adefa67cc697c09d0ab137d30 - Patch, Third Party Advisory | |
References | () https://github.com/moby/moby/releases/tag/v19.03.15 - Release Notes, Third Party Advisory | |
References | () https://github.com/moby/moby/releases/tag/v20.10.3 - Release Notes, Third Party Advisory | |
References | () https://github.com/moby/moby/security/advisories/GHSA-6fj5-m822-rqx8 - Third Party Advisory | |
References | () https://security.gentoo.org/glsa/202107-23 - Patch, Third Party Advisory | |
References | () https://security.netapp.com/advisory/ntap-20210226-0005/ - Third Party Advisory | |
References | () https://www.debian.org/security/2021/dsa-4865 - Third Party Advisory |
Information
Published : 2021-02-02 18:15
Updated : 2024-11-21 05:47
NVD link : CVE-2021-21285
Mitre link : CVE-2021-21285
CVE.ORG link : CVE-2021-21285
JSON object : View
Products Affected
docker
- docker
debian
- debian_linux
netapp
- e-series_santricity_os_controller