GPU VulnDB

Database/Container, Kubernetes & orchestration

Docker Engine: DNS any-match on insecure-registry CIDRs disables TLS for registry pulls

CVSS 7.6CVE-2026-92543Container, Kubernetes & orchestrationcurated

Impact

Docker Engine treats a registry hostname as insecure if any one of the addresses DNS returns for it falls inside the insecure CIDR list, and 127.0.0.0/8 and ::1/128 are in that list by default. Because the transport then re-dials the hostname instead of the address that matched, an attacker who controls the DNS answer set can return one loopback address plus their own routable address and have the daemon drop certificate verification and fall back to plain HTTP. On a GPU node that means image pulls - CUDA base images, inference server images, model sidecars - can be served by an attacker in the network path with no TLS error. A substituted image on a shared GPU host is code execution in whatever that container is privileged to do, which on GPU nodes usually includes device access to /dev/nvidia*.

Who can reach it

Network attacker who can influence DNS resolution for a registry hostname the daemon pulls from (or operate the resolver), plus a position to answer the resulting cleartext/untrusted connection. No authentication to the daemon is needed, but the record's CVSS marks user interaction as required - a pull has to happen against the affected hostname.

What to do

Update Docker Engine / Moby to the fixed release named in the Moby advisory (the record does not state the version - read GHSA-7cfq-22r6-qp73 before scheduling) and restart dockerd, which stops running containers on that host unless live-restore is enabled; on Kubernetes GPU nodes treat it as a cordon-and-drain before the runtime restart. Until then, audit daemon.json for insecure-registries entries, pin registries to IP literals or trusted internal resolvers, and keep registry DNS off resolvers an attacker can influence.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.