REDHAT-BUG-2488484: Race Condition
Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to redirect a bind mount target to an arbitrary host path, potentially overwriting host files or causing denial of service. This issue has been patched in Docker Engine version 29.5.1 and Moby Daemon version 2.0.0-beta.14.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Docker Engineto a version that resolves this vulnerability.Fixed in 29.5.1 - Upgrade
Upgrade
Moby Daemonto a version that resolves this vulnerability.Fixed in 2.0.0-beta.14
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2488484?
The severity of REDHAT-BUG-2488484 is classified as high, with a score of 7.
How do I fix REDHAT-BUG-2488484?
To fix REDHAT-BUG-2488484, update Docker Engine to version 29.5.1 or higher, Docker Daemon to version 28.5.3 or higher, and Moby Daemon to version 2.0.0-beta.14 or higher.
What software is affected by REDHAT-BUG-2488484?
The affected software includes Docker Engine, Docker Daemon, and Moby Daemon.
What type of vulnerability is REDHAT-BUG-2488484?
REDHAT-BUG-2488484 is categorized as a race condition vulnerability.
When was REDHAT-BUG-2488484 published?
REDHAT-BUG-2488484 was published on June 12, 2026.