CVE-2021-32760
Docker vulnerability analysis and mitigation

Overview

A bug was found in containerd versions prior to 1.4.8 and 1.5.4 where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing files in the host's filesystem (GitHub Advisory, NVD).

Technical details

The vulnerability exists in the archive package of containerd where file permission changes can affect files outside of the unpack target directory. The issue allows changes to file permissions that can deny access to the expected owner of the file, widen access to others, or set extended bits like setuid, setgid, and sticky. This vulnerability does not directly allow files to be read, modified, or executed without an additional cooperating process (GitHub Advisory).

Impact

The vulnerability can result in unauthorized file permission modifications on the host system. Changes to file permissions can deny access to the expected owner of the file, widen access to others, or set extended bits like setuid, setgid, and sticky bits on existing files in the host's filesystem (GitHub Advisory, Ubuntu Security).

Exploitability

The vulnerability can be exploited if a user or automated system is tricked into launching a specially crafted container image. The exploitation does not directly allow files to be read, modified, or executed without an additional cooperating process (Ubuntu Security).

Mitigation and workarounds

Users should update to containerd versions 1.5.4 or 1.4.8 or later. Running containers do not need to be restarted. As a workaround, users should ensure they only pull images from trusted sources. Linux security modules (LSMs) like SELinux and AppArmor can limit the files potentially affected through policies and profiles that prevent containerd from interacting with unexpected files (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Docker vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-56852HIGH7.5
  • cAdvisor logocAdvisor
  • crossplane-provider-aws-sfn
NoYesJul 21, 2026
CVE-2026-15793HIGH7.3
  • Docker logoDocker
  • runfinch-finch
NoYesJul 21, 2026
CVE-2026-17106HIGH7.1
  • Docker logoDocker
  • kubescape-server
NoYesAug 18, 2026
CVE-2026-15792MEDIUM6
  • Docker logoDocker
  • docker.io-app
NoYesJul 21, 2026
CVE-2026-15791LOW1.8
  • Docker logoDocker
  • buildkit
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management