Home / mailings [SECURITY] [DSA 6443-1] docker.io security update
Posted on 16 August 2026
Debian Security Advisory- -------------------------------------------------------------------------
Debian Security Advisory DSA-6443-1 security@debian.org
https://www.debian.org/security/ Aron Xu
August 16, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : docker.io
CVE ID : CVE-2026-33747 CVE-2026-33748 CVE-2026-33997 CVE-2026-34040
CVE-2026-41567 CVE-2026-41568 CVE-2026-42306
Multiple vulnerabilities were discovered in the Docker container engine
and in the bundled BuildKit build toolkit, which may result in privilege
escalation, arbitrary file access on the host, or bypass of authorization
policies.
For the stable distribution (trixie), these problems have been fixed in
version 26.1.5+dfsg1-9+deb13u1.
We recommend that you upgrade your docker.io packages.
For the detailed security status of docker.io please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/docker.io
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
