Database/Container, Kubernetes & orchestration
Docker / moby: /var/lib/docker subdirectories world-traversable
CVSS 6.3CVE-2021-41091Container, Kubernetes & orchestrationcurated
Impact
/var/lib/docker subdirectories world-traversable; unprivileged host user reaches container filesystems
Who can reach it
Any local user on the node
What to do
Upgrade Docker Engine and fix directory modes
References
Related entries
- Docker / moby: Companion `docker cp` mount-setup raceCVE-2026-41568 · Docker / mobyMedium
- Docker / moby: Containers started with non-empty inheritable capabilitiesCVE-2022-24769 · Docker / mobyMedium
- Docker / moby: DNS requests from an internal network can be forwarded to external resolvers, leaking data outCVE-2024-29018 · Docker / mobyMedium
- Docker / moby: Default OCI spec does not mask /proc/acpi, so a container can change host hardware stateCVE-2018-10892 · Docker / mobyMedium
- Docker / moby: Supplementary groups not set up properlyCVE-2022-36109 · Docker / mobyMedium
- Docker / moby: On firewalld reload, published container ports become reachable from outside despite the intendedCVE-2025-54388 · Docker / mobyMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.