The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extrac…
提示
摘要
The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extractor decides where each archive entry lands using lexical string checks and then performs the filesystem operation on a path that is resolved by the OS, so links introduced by the archive can be followed out of the destination directory. An attacker who controls the contents of an archive can create …
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
数据来源
- NVD DATABASE
原始链接
- https://docs.docker.com/desktop/release-notes/#4860
- https://docs.docker.com/engine/release-notes/29/#2970
- https://github.com/docker/cli/releases/tag/v29.7.0
- https://github.com/docker/compose/releases/tag/v5.4.0
- https://github.com/docker/sbx-releases/releases/tag/v0.38.0
- https://github.com/moby/go-archive/releases/tag/v0.3.0
- https://github.com/moby/go-archive/security/advisories/GHSA-hfg8-hc9c-6c3h
- https://github.com/masasron/CopyEscape-CVE-2026-17106
时间线
- nvd_ingest NVD