[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index] [SECURITY] [DSA 6443-1] docker.io security update To: debian-security-announce@lists.debian.org Subject: [SECURITY] [DSA 6443-1] docker.io security update From: Aron Xu <aron@debian.org> Date: Sun, 16 Aug 2026 08:58:52 +0000 Message-id: <[🔎] E1wvWhg-0000000GZdB-37KI@seger.debian.org> Reply-to: debian-security-announce-request@lists.debian.org -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6443-1 security@debian.org https://www.debian.org/security/ Aron Xu August 16, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : docker.io CVE ID : CVE-2026-33747 CVE-2026-33748 CVE-2026-33997 CVE-2026-34040 CVE-2026-41567 CVE-2026-41568 CVE-2026-42306 Multiple vulnerabilities were discovered in the Docker container engine and in the bundled BuildKit build toolkit, which may result in privilege escalation, arbitrary file access on the host, or bypass of authorization policies. For the stable distribution (trixie), these problems have been fixed in version 26.1.5+dfsg1-9+deb13u1. We recommend that you upgrade your docker.io packages. For the detailed security status of docker.io please refer to its security tracker page at: https://security-tracker.debian.org/tracker/docker.io Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQEzBAEBCAAdFiEExq6D0hxncEPaPayX+GQ1dHE8m64FAmqBeuAACgkQ+GQ1dHE8 m65VTwgAjidgYsQsNvX39I+1PE1amNWY6079+IDHIMvZbqJA9e90ZbKe+VNDZKhK iSyiqxbAWZ4bYZtkfK8uE0geu8y/Zgz5S4RDGrY3jK4WaTa1N/OP/d93lnCxmAIo ns91h+z5wMIt3eFDucwby8IXWl9mepzKbKP2CTTHMvQcvxSau+xq5iI4S86vIzuX kNb/PYE2zSw02oznSURvq9l3QmC+jFwwr7Lgyo55mLb5ZWSw/gJPdKZIwpPskzN2 cRbHff25frLkjkxUk4q3hOmDCAG9YGYCx2OQen+mTwiQ8erFnXQmQzfHBhc11tgU 46d8Th+oTxptO8xQFm8aOAJPKrK9wQ== =4MaX -----END PGP SIGNATURE----- Reply to: debian-security-announce@lists.debian.org Aron Xu (on-list) Aron Xu (off-list) Prev by Date: [SECURITY] [DSA 6442-1] util-linux security update Previous by thread: [SECURITY] [DSA 6442-1] util-linux security update Index(es): Date Thread
Multiple vulnerabilities in Docker and its BuildKit toolkit (CVE-2026-33747, CVE-2026-33748, CVE-2026-33997, etc.) could lead to privilege escalation, arbitrary host file access, or authorization bypass. The CVSS scores range from High (8.4) to Medium (6.8). For Debian stable (trixie), these are fixed in docker.io version 26.1.5+dfsg1-9+deb13u1.