USN-7474-1

Advisory lineage Upstream: 14 Downstream: 0
Published: 01 May 2025, 13:54
Last modified:27 Apr 2026, 17:57

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

01 May 2025, 13:54
Published
Vulnerability first disclosed
27 Apr 2026, 17:57
Last Modified
Vulnerability information updated

Description

docker.io vulnerabilities Cory Snider discovered that Docker incorrectly handled networking packet encapsulation. An attacker could use this issue to inject internet packets in established connection, possibly causing a denial of service or bypassing firewall protections. This issue only affected Ubuntu 22.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 18.04 LTS. (CVE-2023-28840, CVE-2023-28841, CVE-2023-28842) Rory McNamara discovered that Docker incorrectly handled cache in the BuildKit toolkit. An attacker could possibly use this issue to expose sensitive information. (CVE-2024-23651) It was discovered that Docker incorrectly handled parallel operations in some circumstances, which could possibly lead to undefined behavior. (CVE-2024-36621, CVE-2024-36623) Rory McNamara discovered that Docker incorrectly verified file paths during a certain command in the BuildKit toolkit. An attacker could possibly use this issue to delete arbitrary files from the system. (CVE-2024-23652)

Affected Systems

  • ubuntudocker.io

    < 20.10.21-0ubuntu1~18.04.3+esm3 | < 20.10.21-0ubuntu1~20.04.6+esm2 | < 20.10.21-0ubuntu1~22.04.7+esm2 | < 20.10.25+dfsg1-2ubuntu1+esm2

References (8)