Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Ubuntu 21.10 USN-5134-1: Docker Information Disclosure Threat

Ubuntu Large Esm H500
Docker could be made to expose sensitive information over the network.
=========================================================================
Ubuntu Security Notice USN-5134-1
November 09, 2021

docker.io vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 21.10
- Ubuntu 21.04
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

Docker could be made to expose sensitive information over the
network.

Software Description:
- docker.io: Linux container runtime

Details:

An information disclosure issue was discovered in the command line interface
of Docker. A misconfigured credential store could result in supplied
credentials being leaked to the public registry, when using the docker login
command with a private registry.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 21.10:
docker.io 20.10.7-0ubuntu5.1

Ubuntu 21.04:
docker.io 20.10.7-0ubuntu5~21.04.2

Ubuntu 20.04 LTS:
docker.io 20.10.7-0ubuntu5~20.04.2

Ubuntu 18.04 LTS:
docker.io 20.10.7-0ubuntu5~18.04.3

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5134-1
CVE-2021-41092

Package Information:
https://launchpad.net/ubuntu/+source/docker.io/20.10.7-0ubuntu5.1
https://launchpad.net/ubuntu/+source/docker.io/20.10.7-0ubuntu5~21.04.2
https://launchpad.net/ubuntu/+source/docker.io/20.10.7-0ubuntu5~20.04.2
https://launchpad.net/ubuntu/+source/docker.io/20.10.7-0ubuntu5~18.04.3

Ubuntu 21.10 USN-5134-1: Docker Information Disclosure Threat

ubuntu
Calendar Grey November 9, 2021
Dist Ubuntu Esm H88
A critical exposure flaw in Docker impacts several variants of Ubuntu. Ensure systems are updated to reduce potential threats.
Docker could be made to expose sensitive information over the network.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 21.10: docker.io 20.10.7-0ubuntu5.1 Ubuntu 21.04: docker.io 20.10.7-0ubuntu5~21.04.2 Ubuntu 20.04 LTS: docker.io 20.10.7-0ubuntu5~20.04.2 Ubuntu 18.04 LTS: docker.io 20.10.7-0ubuntu5~18.04.3 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5134-1

CVE-2021-41092

Severity
important
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-5134-1

Package Information

https://launchpad.net/ubuntu/+source/docker.io/20.10.7-0ubuntu5.1 https://launchpad.net/ubuntu/+source/docker.io/20.10.7-0ubuntu5~21.04.2 https://launchpad.net/ubuntu/+source/docker.io/20.10.7-0ubuntu5~20.04.2 https://launchpad.net/ubuntu/+source/docker.io/20.10.7-0ubuntu5~18.04.3

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here