Back to Database
Status published
Medium
CVE-2021-21285
Docker daemon crash during image pull of malicious image
Vulnerability Description
In Docker before versions 9.03.15, 20.10.3 there is a vulnerability in which pulling an intentionally malformed Docker image manifest crashes the dockerd daemon. Versions 20.10.3 and 19.03.15 contain patches that prevent the daemon from crashing.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-21285
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/moby/moby/security/advisories/GHSA-6fj5-m822-rqx8
- https://docs.docker.com/engine/release-notes/#20103
- https://github.com/moby/moby/releases/tag/v20.10.3
- https://github.com/moby/moby/releases/tag/v19.03.15
- https://github.com/moby/moby/commit/8d3179546e79065adefa67cc697c09d0ab137d30
- https://security.netapp.com/advisory/ntap-20210226-0005/
- https://www.debian.org/security/2021/dsa-4865
- https://security.gentoo.org/glsa/202107-23
More from moby
View All →CVE-2025-54410
Moby's Firewalld reload removes bridge network isolation
Low
3.3
CVE-2025-54388
Moby's Firewalld reload makes published container ports accessible from remote hosts
Medium
5.1
CVE-2024-41110
Moby authz zero length regression
Critical
10
CVE-2024-32473
Moby IPv6 enabled on IPv4-only network interfaces
Medium
4.7
CVE-2024-29018
External DNS requests from 'internal' networks could lead to data exfiltration
Medium
5.9
Affected Vendor
moby
View all reports →Affected Software
moby
Vulnerable Versions:
< 19.03.15, >= 20.0.0, < 20.10.3
Timeline
Official Publish:
February 2nd, 2021
Last Modified:
August 3rd, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H