What is CVE-2026-18171?
CVE-2026-18171 affects Docker Sandboxes (sbx) where a read-only host mount is incorrectly applied only to the container bind, leaving the underlying virtio-fs share writable. This allows unprivileged guest code to write to the host filesystem. Affected users should apply the latest security patches immediately.
Azərbaycanca: CVE-2026-18171 Docker Sandboxes (sbx) zəifliyi host-da yalnız oxunaqlı (read-only) olaraq mount edilmiş kataloqun qonaq konteynerə yazıla bilən olaraq ötürülməsinə səbəb olur. Bu, imtiyazsız kodun host fayl sisteminə yazmasına imkan yaradır. Təsirə məruz qalmamaq üçün Docker Sandboxes istifadəçiləri təhlükəsizlik yeniləmələrini dərhal tətbiq etməlidirlər.
Related CVEs
link basis: same weakness class CWE-732
FAQ1
How does CVE-2026-18171 affect the host filesystem in Docker Sandboxes?
This vulnerability causes a read-only host mount to be passed to the guest container as writable, allowing unprivileged guest code to write to the host filesystem.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.