SB2025082120 - Security restrictions bypass in Docker Desktop
Published: August 21, 2025 Updated: January 9, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2025-9074)
The vulnerability allows a malicious container to execute arbitrary code on the system.
The vulnerability exists due to improperly imposed security restrictions. A malicious container can access the Docker Engine and launch additional containers without requiring the Docker socket to be mounted, leading to unauthorized access to files on the host system.
Remediation
Install update from vendor's website.