PT-2014-8957 · Docker+1 · Docker+1

Published

2014-12-16

·

Updated

2025-10-11

·

CVE-2014-9357

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Docker version 1.3.2
Description The issue allows remote attackers to execute arbitrary code with root privileges. This can be achieved via a crafted image or build in a Dockerfile, specifically when the image or build is contained in an LZMA (.xz) archive. The problem is related to the chroot used for archive extraction.
Recommendations For Docker version 1.3.2, consider restricting the use of LZMA (.xz) archives until a patch is available. As a temporary workaround, avoid using crafted images or builds in Dockerfiles that could exploit this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2014-9357
GHSA-997C-FJ8J-RQ5H
GO-2022-0640
OPENSUSE-SU-2024:10532-1
OPENSUSE-SU-2025:15589-1
RHSA-2015:0623
SUSE-SU-2025:03540-1
SUSE-SU-2025:03545-1

Affected Products

Docker
Suse