DSA-6443-1 docker.io - security update
Multiple vulnerabilities were discovered in the Docker container engine and in the bundled BuildKit build toolkit, which may result in privilege escalation, arbitrary file access on the host, or bypass of authorization policies. https://security-tracker.debian.org/tracker/DSA-6443-1
CSIRTS triage
- What
- Multiple vulnerabilities in Docker container engine and bundled BuildKit toolkit allow privilege escalation, arbitrary file access on the host, and authorization policy bypass.
- Who is affected
- Deployments using affected versions of Docker container engine and BuildKit on Debian systems.
- Urgency
- High urgency due to privilege escalation and host file access capabilities; exploitation status unknown but impact is severe.
- Action
- Apply the Debian security update DSA-6443-1 or upgrade to patched Docker version.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch docker.io
Get an email when a new docker.io advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00354.html
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-337470.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-337480.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-339970.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Elevated exploitation riskCVE-2026-3404010.1% 30-day exploitation probability — well above the norm. Schedule remediation this cycle. Riskier than 95% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-415670.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-415680.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-423060.10% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-33747 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-33748 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-33997 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-34040 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-41567 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-41568 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-42306 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[UPDATE] [medium] docker: Multiple Vulnerabilitiescert-bund
- high[UPDATE] [high] docker: Multiple vulnerabilitiescert-bund
More from Debian Security Advisories
- unknownDSA-6444-1 neutron - security update2026-08-16
- unknownDSA-6442-1 util-linux - security update2026-08-14
- unknownDSA-6440-1 unzip - security update2026-08-14
- unknownDSA-6441-1 python-httplib2 - security update2026-08-14
- unknownDSA-6439-1 zip - security update2026-08-14