CVE-2026-42306
Public on 2026-05-27
Modified on 2026-05-27
Description
Docker: Race condition in docker cp allows bind mount redirection to host path
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Ecs Extra | docker | Pending Fix | ||
| Amazon Linux 2 - Docker Extra | docker | 2026-06-08 | ALAS2DOCKER-2026-126 | Fixed |
| Amazon Linux 2 - Aws-nitro-enclaves-cli Extra | docker | 2026-06-08 | ALAS2NITRO-ENCLAVES-2026-108 | Fixed |
| Amazon Linux 2023 | docker | 2026-06-08 | ALAS2023-2026-1783 | Fixed |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 7.2 | CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:H |
| NVD | CVSSv3 | 7.2 | CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:H |