Pulling an intentionally malformed Docker image manifest crashes the dockerd
daemon.
Versions 20.10.3 and 19.03.15 contain patches that prevent the daemon from crashing.
Maintainers would like to thank Josh Larsen, Ian Coldwater, Duffie Cooley, Rory McCune for working on the vulnerability and Brad Geesaman for responsibly disclosing it to security@docker.com.
{ "nvd_published_at": "2021-02-02T18:15:00Z", "cwe_ids": [ "CWE-400", "CWE-754" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-01-31T23:16:46Z" }