CVE-2021-21284
published 2021-02-02CVE-2021-21284: In Docker before versions 9.03.15, 20.10.3 there is a vulnerability involving the --userns-remap option in which access to remapped root allows privilege…
PriorityP432medium6.8CVSS 3.1
AVAACLPRLUINSCCNIHAN
EPSS
1.06%
60.9th percentile
In Docker before versions 9.03.15, 20.10.3 there is a vulnerability involving the --userns-remap option in which access to remapped root allows privilege escalation to real root. When using "--userns-remap", if the root user in the remapped namespace has access to the host filesystem they can modify files under "/var/lib/docker/" that cause writing files with extended privileges. Versions 20.10.3 and 19.03.15 contain patches that prevent privilege escalation from remapped user.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | docker.io | < docker.io 20.10.3+dfsg1-1 (bookworm) | docker.io 20.10.3+dfsg1-1 (bookworm) |
| docker | docker | < 19.03.15 | 19.03.15 |
| docker | docker | >= 20.0.0 < 20.10.3 | 20.10.3 |
| github.com | moby_moby | >= 0 < 19.3.15 | 19.3.15 |
| github.com | moby_moby | >= 20.10.0-beta1 < 20.10.3 | 20.10.3 |
| moby | moby | < 19.03.15 | 19.03.15 |
| moby | moby | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_moby-buildx_0.4.1+azure-3_on_cbl_mariner_1.0 | — | — |
| msrc | cm1_moby-cli_19.03.15+azure-2_on_cbl_mariner_1.0 | — | — |
| msrc | cm1_moby-engine_19.03.15+azure-2_on_cbl_mariner_1.0 | — | — |
| netapp | e-series_santricity_os_controller | 11.0.0 – 11.60.3 | — |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
nvdv2.02.7LOWAV:A/AC:L/Au:S/C:N/I:P/A:N
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_msrc6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
privilege escalation in Moby
vendor_msrc·2021-02-09·CVSS 6.8
CVE-2021-21284 [MEDIUM] CWE-22 privilege escalation in Moby
privilege escalation in Moby
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/
Red Hat
docker: access to remapped root allows privilege escalation to real root
vendor_redhat·2021-02-02·CVSS 6.8
CVE-2021-21284 [MEDIUM] CWE-732 docker: access to remapped root allows privilege escalation to real root
docker: access to remapped root allows privilege escalation to real root
In Docker before versions 9.03.15, 20.10.3 there is a vulnerability involving the --userns-remap option in which access to remapped root allows privilege escalation to real root. When using "--userns-remap", if the root user in the remapped namespace has access to the host filesystem they can modify files under "/var/lib/docker/" that cause writing files with extended privileges. Versions 20.10.3 and 19.03.15 contain patches that prevent privilege escalation from remapped user.
A flaw was found in the `userns-remap` feature of Docker. The root user in the remapped namespace can modify files under /var/lib/docker/, leading to possible privilege escalation to the root user in the host. The highest threat from this vul
Debian
CVE-2021-21284: docker.io - In Docker before versions 9.03.15, 20.10.3 there is a vulnerability involving th...
vendor_debian·2021·CVSS 6.8
CVE-2021-21284 [MEDIUM] CVE-2021-21284: docker.io - In Docker before versions 9.03.15, 20.10.3 there is a vulnerability involving th...
In Docker before versions 9.03.15, 20.10.3 there is a vulnerability involving the --userns-remap option in which access to remapped root allows privilege escalation to real root. When using "--userns-remap", if the root user in the remapped namespace has access to the host filesystem they can modify files under "/var/lib/docker/" that cause writing files with extended privileges. Versions 20.10.3 and 19.03.15 contain patches that prevent privilege escalation from remapped user.
Scope: local
bookworm: resolved (fixed in 20.10.3+dfsg1-1)
bullseye: resolved (fixed in 20.10.3+dfsg1-1)
forky: resolved (fixed in 20.10.3+dfsg1-1)
sid: resolved (fixed in 20.10.3+dfsg1-1)
trixie: resolved (fixed in 20.10.3+dfsg1-1)
GHSA
moby Access to remapped root allows privilege escalation to real root
ghsa·2024-01-31
CVE-2021-21284 [MEDIUM] CWE-22 moby Access to remapped root allows privilege escalation to real root
moby Access to remapped root allows privilege escalation to real root
### Impact
When using `--userns-remap`, if the root user in the remapped namespace has access to the host filesystem they can modify files under `/var/lib/docker/` that cause writing files with extended privileges.
### Patches
Versions 20.10.3 and 19.03.15 contain patches that prevent privilege escalation from remapped user.
### Credits
Maintainers would like to thank Alex Chapman for discovering the vulnerability; @awprice, @nathanburrell, @raulgomis, @chris-walz, @erin-jensby, @bassmatt, @mark-adams, @dbaxa for working on it and Zac Ellis for responsibly disclosing it to [email protected]
OSV
moby Access to remapped root allows privilege escalation to real root
osv·2024-01-31
CVE-2021-21284 [MEDIUM] moby Access to remapped root allows privilege escalation to real root
moby Access to remapped root allows privilege escalation to real root
### Impact
When using `--userns-remap`, if the root user in the remapped namespace has access to the host filesystem they can modify files under `/var/lib/docker/` that cause writing files with extended privileges.
### Patches
Versions 20.10.3 and 19.03.15 contain patches that prevent privilege escalation from remapped user.
### Credits
Maintainers would like to thank Alex Chapman for discovering the vulnerability; @awprice, @nathanburrell, @raulgomis, @chris-walz, @erin-jensby, @bassmatt, @mark-adams, @dbaxa for working on it and Zac Ellis for responsibly disclosing it to [email protected]
OSV
CVE-2021-21284: In Docker before versions 9
osv·2021-02-02·CVSS 6.8
CVE-2021-21284 [MEDIUM] CVE-2021-21284: In Docker before versions 9
In Docker before versions 9.03.15, 20.10.3 there is a vulnerability involving the --userns-remap option in which access to remapped root allows privilege escalation to real root. When using "--userns-remap", if the root user in the remapped namespace has access to the host filesystem they can modify files under "/var/lib/docker/" that cause writing files with extended privileges. Versions 20.10.3 and 19.03.15 contain patches that prevent privilege escalation from remapped user.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://docs.docker.com/engine/release-notes/#20103https://github.com/moby/moby/commit/64bd4485b3a66a597c02c95f5776395e540b2c7chttps://github.com/moby/moby/releases/tag/v19.03.15https://github.com/moby/moby/releases/tag/v20.10.3https://github.com/moby/moby/security/advisories/GHSA-7452-xqpj-6rpchttps://security.gentoo.org/glsa/202107-23https://security.netapp.com/advisory/ntap-20210226-0005/https://www.debian.org/security/2021/dsa-4865https://docs.docker.com/engine/release-notes/#20103https://github.com/moby/moby/commit/64bd4485b3a66a597c02c95f5776395e540b2c7chttps://github.com/moby/moby/releases/tag/v19.03.15https://github.com/moby/moby/releases/tag/v20.10.3https://github.com/moby/moby/security/advisories/GHSA-7452-xqpj-6rpchttps://security.gentoo.org/glsa/202107-23https://security.netapp.com/advisory/ntap-20210226-0005/https://www.debian.org/security/2021/dsa-4865
2021-02-02
Published