Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to redirect a bind mount target to an arbitrary host path, potentially overwriting host files or causing denial of service. This issue has been patched in Docker Engine version 29.5.1 and Moby Daemon version 2.0.0-beta.14.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-rg2x-37c3-w2rh | Docker: Race condition in docker cp allows bind mount redirection to host path |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 12 Jun 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Moby
Moby moby |
|
| Vendors & Products |
Moby
Moby moby |
Fri, 12 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to redirect a bind mount target to an arbitrary host path, potentially overwriting host files or causing denial of service. This issue has been patched in Docker Engine version 29.5.1 and Moby Daemon version 2.0.0-beta.14. | |
| Title | Moby: Race condition in docker cp allows bind mount redirection to host path | |
| Weaknesses | CWE-367 CWE-61 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-12T18:09:22.188Z
Reserved: 2026-04-26T12:37:18.169Z
Link: CVE-2026-42306
No data.
Status : Received
Published: 2026-06-12T19:16:27.490
Modified: 2026-06-12T19:16:27.490
Link: CVE-2026-42306
No data.
OpenCVE Enrichment
Updated: 2026-06-12T21:00:20Z
Github GHSA