USN-7161-2

Source
https://ubuntu.com/security/notices/USN-7161-2
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7161-2.json
JSON Data
https://api.osv.dev/v1/vulns/USN-7161-2
Related
Published
2025-02-18T08:22:46.729798Z
Modified
2025-02-18T08:22:46.729798Z
Summary
Docker vulnerabilities
Details

USN-7161-1 fixed CVE-2024-29018 in Ubuntu 24.04 LTS. This update fixes it in Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 24.10, and Ubuntu 24.04 LTS.

USN-7161-1 fixed CVE-2024-41110 in Ubuntu 24.10, Ubuntu 24.04 LTS, and Ubuntu 18.04 LTS. This updates fixes it in Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.

Original advisory details:

Yair Zak discovered that Docker could unexpectedly forward DNS requests from internal networks in an unexpected manner. An attacker could possibly use this issue to exfiltrate data by encoding information in DNS queries to controlled nameservers. This issue was only addressed in Ubuntu 24.04 LTS. (CVE-2024-29018)

Cory Snider discovered that Docker did not properly handle authorization plugin request processing. An attacker could possibly use this issue to bypass authorization controls by forwarding API requests without their full body, leading to unauthorized actions. (CVE-2024-41110)

References

Affected packages

Ubuntu:Pro:16.04:LTS / docker.io

Package

Name
docker.io
Purl
pkg:deb/ubuntu/docker.io@18.09.7-0ubuntu1~16.04.9+esm2?arch=source&distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
18.09.7-0ubuntu1~16.04.9+esm2

Affected versions

1.*

1.6.2~dfsg1-1ubuntu4
1.10.2-0ubuntu3
1.10.2-0ubuntu4
1.10.3-0ubuntu1
1.10.3-0ubuntu4
1.10.3-0ubuntu5
1.10.3-0ubuntu6
1.11.2-0ubuntu5~16.04
1.12.1-0ubuntu13~16.04.1
1.12.3-0ubuntu4~16.04.2
1.12.6-0ubuntu1~16.04.1
1.13.1-0ubuntu1~16.04.2

17.*

17.03.2-0ubuntu2~16.04.1

18.*

18.06.1-0ubuntu1~16.04.2
18.06.1-0ubuntu1.2~16.04.1
18.09.2-0ubuntu1~16.04.1
18.09.5-0ubuntu1~16.04.2
18.09.7-0ubuntu1~16.04.1
18.09.7-0ubuntu1~16.04.4
18.09.7-0ubuntu1~16.04.5
18.09.7-0ubuntu1~16.04.6
18.09.7-0ubuntu1~16.04.7
18.09.7-0ubuntu1~16.04.9+esm1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "18.09.7-0ubuntu1~16.04.9+esm2",
            "binary_name": "docker-doc"
        },
        {
            "binary_version": "18.09.7-0ubuntu1~16.04.9+esm2",
            "binary_name": "docker.io"
        },
        {
            "binary_version": "18.09.7-0ubuntu1~16.04.9+esm2",
            "binary_name": "golang-docker-dev"
        },
        {
            "binary_version": "18.09.7-0ubuntu1~16.04.9+esm2",
            "binary_name": "golang-github-docker-docker-dev"
        },
        {
            "binary_version": "18.09.7-0ubuntu1~16.04.9+esm2",
            "binary_name": "vim-syntax-docker"
        }
    ]
}

Ubuntu:Pro:18.04:LTS / docker.io

Package

Name
docker.io
Purl
pkg:deb/ubuntu/docker.io@20.10.21-0ubuntu1~18.04.3+esm2?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20.10.21-0ubuntu1~18.04.3+esm2

Affected versions

1.*

1.13.1-0ubuntu6

17.*

17.03.2-0ubuntu1
17.03.2-0ubuntu3
17.03.2-0ubuntu5
17.12.1-0ubuntu1

18.*

18.06.1-0ubuntu1~18.04.1
18.06.1-0ubuntu1.2~18.04.1
18.09.2-0ubuntu1~18.04.1
18.09.5-0ubuntu1~18.04.2
18.09.7-0ubuntu1~18.04.1
18.09.7-0ubuntu1~18.04.3
18.09.7-0ubuntu1~18.04.4

19.*

19.03.6-0ubuntu1~18.04.1
19.03.6-0ubuntu1~18.04.2
19.03.6-0ubuntu1~18.04.3

20.*

20.10.2-0ubuntu1~18.04.2
20.10.2-0ubuntu1~18.04.3
20.10.7-0ubuntu1~18.04.1
20.10.7-0ubuntu1~18.04.2
20.10.7-0ubuntu5~18.04.2
20.10.7-0ubuntu5~18.04.3
20.10.12-0ubuntu2~18.04.1
20.10.21-0ubuntu1~18.04.2
20.10.21-0ubuntu1~18.04.3
20.10.21-0ubuntu1~18.04.3+esm1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "20.10.21-0ubuntu1~18.04.3+esm2",
            "binary_name": "docker-doc"
        },
        {
            "binary_version": "20.10.21-0ubuntu1~18.04.3+esm2",
            "binary_name": "docker.io"
        },
        {
            "binary_version": "20.10.21-0ubuntu1~18.04.3+esm2",
            "binary_name": "golang-docker-dev"
        },
        {
            "binary_version": "20.10.21-0ubuntu1~18.04.3+esm2",
            "binary_name": "golang-github-docker-docker-dev"
        },
        {
            "binary_version": "20.10.21-0ubuntu1~18.04.3+esm2",
            "binary_name": "vim-syntax-docker"
        }
    ]
}

Ubuntu:Pro:20.04:LTS / docker.io-app

Package

Name
docker.io-app
Purl
pkg:deb/ubuntu/docker.io-app@26.1.3-0ubuntu1~20.04.1+esm1?arch=source&distro=esm-apps/focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
26.1.3-0ubuntu1~20.04.1+esm1

Affected versions

20.*

20.10.25-0ubuntu1~20.04.1
20.10.25-0ubuntu1~20.04.2

24.*

24.0.5-0ubuntu1~20.04.1
24.0.7-0ubuntu2~20.04.1

26.*

26.1.3-0ubuntu1~20.04.1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "26.1.3-0ubuntu1~20.04.1+esm1",
            "binary_name": "docker-doc"
        },
        {
            "binary_version": "26.1.3-0ubuntu1~20.04.1+esm1",
            "binary_name": "docker.io"
        },
        {
            "binary_version": "26.1.3-0ubuntu1~20.04.1+esm1",
            "binary_name": "docker.io-dbgsym"
        }
    ]
}

Ubuntu:Pro:22.04:LTS / docker.io-app

Package

Name
docker.io-app
Purl
pkg:deb/ubuntu/docker.io-app@26.1.3-0ubuntu1~22.04.1+esm1?arch=source&distro=esm-apps/jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
26.1.3-0ubuntu1~22.04.1+esm1

Affected versions

20.*

20.10.25-0ubuntu1~22.04.1
20.10.25-0ubuntu1~22.04.2

24.*

24.0.5-0ubuntu1~22.04.1
24.0.7-0ubuntu2~22.04.1

26.*

26.1.3-0ubuntu1~22.04.1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "26.1.3-0ubuntu1~22.04.1+esm1",
            "binary_name": "docker-doc"
        },
        {
            "binary_version": "26.1.3-0ubuntu1~22.04.1+esm1",
            "binary_name": "docker.io"
        },
        {
            "binary_version": "26.1.3-0ubuntu1~22.04.1+esm1",
            "binary_name": "docker.io-dbgsym"
        }
    ]
}