CopyEscape Docker Flaw Lets Malicious Containers Overwrite Host Files and Gain Root Access

A Docker flaw, CVE-2026-17106 (dubbed CopyEscape), lets malicious containers write files outside the docker cp destination, potentially enabling code execution and root-level compromise. The issue affects Docker’s archive extraction handling in moby/go-archive. When users copy files from a container to a host, Docker does not perform a simple direct transfer. The Docker daemon first packages […]

This article has been indexed from Cyber Security News

Read the original article: