cbcvebase.
CVE-2021-21285
published 2021-02-02

CVE-2021-21285: In Docker before versions 9.03.15, 20.10.3 there is a vulnerability in which pulling an intentionally malformed Docker image manifest crashes the dockerd…

medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
In Docker before versions 9.03.15, 20.10.3 there is a vulnerability in which pulling an intentionally malformed Docker image manifest crashes the dockerd daemon. Versions 20.10.3 and 19.03.15 contain patches that prevent the daemon from crashing.

Affected

14 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandocker.io< docker.io 20.10.3+dfsg1-1 (bookworm)docker.io 20.10.3+dfsg1-1 (bookworm)
dockerdocker< 19.03.1519.03.15
dockerdocker>= 20.0.0 < 20.10.320.10.3
github.commoby_moby>= 0 < 19.3.1519.3.15
github.commoby_moby>= 20.10.0-beta1 < 20.10.320.10.3
mobymoby< 19.03.1519.03.15
mobymoby
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_moby-buildx_0.4.1+azure-3_on_cbl_mariner_1.0
msrccm1_moby-cli_19.03.15+azure-2_on_cbl_mariner_1.0
msrccm1_moby-engine_19.03.15+azure-2_on_cbl_mariner_1.0
netappe-series_santricity_os_controller11.0 – 11.60.3

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM