cbcvebase.
CVE-2021-21285
published 2021-02-02

CVE-2021-21285: In Docker before versions 9.03.15, 20.10.3 there is a vulnerability in which pulling an intentionally malformed Docker image manifest crashes the dockerd…

PriorityP434medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
3.29%
87.1th percentile
In Docker before versions 9.03.15, 20.10.3 there is a vulnerability in which pulling an intentionally malformed Docker image manifest crashes the dockerd daemon. Versions 20.10.3 and 19.03.15 contain patches that prevent the daemon from crashing.

Affected

14 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandocker.io< docker.io 20.10.3+dfsg1-1 (bookworm)docker.io 20.10.3+dfsg1-1 (bookworm)
dockerdocker< 19.03.1519.03.15
dockerdocker>= 20.0.0 < 20.10.320.10.3
github.commoby_moby>= 0 < 19.3.1519.3.15
github.commoby_moby>= 20.10.0-beta1 < 20.10.320.10.3
mobymoby< 19.03.1519.03.15
mobymoby
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_moby-buildx_0.4.1+azure-3_on_cbl_mariner_1.0
msrccm1_moby-cli_19.03.15+azure-2_on_cbl_mariner_1.0
msrccm1_moby-engine_19.03.15+azure-2_on_cbl_mariner_1.0
netappe-series_santricity_os_controller11.0 – 11.60.3

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.