ZDI-CAN-28379: ZDI-26-150: Docker Desktop for Mac Docker Model Runner Exposed Dangerous Function Denial-of-Service Vulnerability
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Docker Desktop. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.3. The following CVEs are assigned: CVE-2026-28400.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-28379?
The severity of ZDI-CAN-28379 is classified as high due to its potential to create a denial-of-service condition.
How do I fix ZDI-CAN-28379?
To fix ZDI-CAN-28379, users should update Docker Desktop for Mac to the latest version that has addressed the vulnerability.
Who is affected by ZDI-CAN-28379?
ZDI-CAN-28379 affects local users of Docker Desktop for Mac who have the vulnerable Docker Model Runner functionality.
What type of attack does ZDI-CAN-28379 enable?
ZDI-CAN-28379 enables a denial-of-service attack against affected installations of Docker Desktop for Mac.
Is ZDI-CAN-28379 easily exploitable?
Yes, ZDI-CAN-28379 can be exploited by local attackers with the ability to execute low-privileged code.