OESA-2026-2138

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-2138
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-2138.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-2138
Upstream
Published
2026-05-03T09:55:46Z
Modified
2026-05-03T10:16:43.488094Z
Summary
moby security update
Details

Docker is a product for you to build, ship and run any application as a lightweight container.

Security Fix(es):

Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's privilege comparison logic, the daemon may incorrectly accept a privilege set that differs from the one approved by the user. Plugins that request exactly one privilege are also affected, because no comparison is performed at all. This issue has been patched in version 29.3.1.(CVE-2026-33997)

Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patched in version 29.3.1.(CVE-2026-34040)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:24.03-LTS-SP3 / moby

Package

Name
moby
Purl
pkg:rpm/openEuler/moby&distro=openEuler-24.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
25.0.3-48.oe2403sp3

Ecosystem specific

{
    "x86_64": [
        "libnetwork-25.0.3-48.oe2403sp3.x86_64.rpm",
        "moby-25.0.3-48.oe2403sp3.x86_64.rpm",
        "moby-client-25.0.3-48.oe2403sp3.x86_64.rpm",
        "moby-debuginfo-25.0.3-48.oe2403sp3.x86_64.rpm",
        "moby-engine-25.0.3-48.oe2403sp3.x86_64.rpm"
    ],
    "src": [
        "moby-25.0.3-48.oe2403sp3.src.rpm"
    ],
    "aarch64": [
        "libnetwork-25.0.3-48.oe2403sp3.aarch64.rpm",
        "moby-25.0.3-48.oe2403sp3.aarch64.rpm",
        "moby-client-25.0.3-48.oe2403sp3.aarch64.rpm",
        "moby-debuginfo-25.0.3-48.oe2403sp3.aarch64.rpm",
        "moby-engine-25.0.3-48.oe2403sp3.aarch64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2138.json"