Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to create empty files or directories at arbitrary absolute paths on the host filesystem. This issue has been patched in Docker Engine version 29.5.1 and Moby Daemon version 2.0.0-beta.14.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-vp62-88p7-qqf5 | Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 12 Jun 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Moby
Moby moby |
|
| Vendors & Products |
Moby
Moby moby |
Fri, 12 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to create empty files or directories at arbitrary absolute paths on the host filesystem. This issue has been patched in Docker Engine version 29.5.1 and Moby Daemon version 2.0.0-beta.14. | |
| Title | Moby: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap | |
| Weaknesses | CWE-367 CWE-81 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-12T18:08:43.914Z
Reserved: 2026-04-21T14:15:21.957Z
Link: CVE-2026-41568
No data.
Status : Received
Published: 2026-06-12T19:16:26.907
Modified: 2026-06-12T19:16:26.907
Link: CVE-2026-41568
No data.
OpenCVE Enrichment
Updated: 2026-06-12T19:30:31Z
Github GHSA