B
今週中
Docker EngineおよびMobyプロジェクトのGoモジュールにおいて、DNSレスポンスの不適切な処理に起因する高深刻度の脆弱性が修正されました
📌 一言でいうと
Docker EngineおよびMobyプロジェクトのGoモジュールにおいて、DNSレスポンスの不適切な処理に起因する高深刻度の脆弱性が修正されました。この脆弱性を悪用されると、コンテナイメージレジストリへの接続セキュリティが侵害され、認証資格情報の漏洩や、正当なイメージが悪意のあるコンテンツに置き換えられる可能性があります。影響を受けるバージョンはDocker Engine 29.8.2未満およびMoby v2.0.0-beta.25未満です。
🔍該当判定
- 自社でDocker Engineを利用しており、バージョンが29.8.2より古い
- 自社でMoby (Goモジュール) を利用しており、バージョンがv2.0.0-beta.25より古い
- コンテナイメージを管理するレジストリ(保存先)への認証情報をDocker Engine経由で利用している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
ベンダーのセキュリティアドバイザリに従い、Docker Engineをバージョン29.8.2以降、Moby (Go module) をv2.0.0-beta.25以降にアップデートすることを推奨します。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Docker Engine CVE-2026-92543 対応について
お疲れさまです。Docker Engineの脆弱性に関する情報共有です。
■ 概要
DNSレスポンスの処理不備により、コンテナイメージレジストリへの接続が侵害される脆弱性が報告されました。認証情報の漏洩や、悪意のあるイメージへの差し替えが行われるリスクがあります。
■ 影響範囲
- Docker Engine: 29.8.2 未満
- Moby (Go module): v2.0.0-beta.25 未満
■ 対応手順
1. 利用中のDocker EngineおよびMobyのバージョンを確認してください。
2. 脆弱なバージョンを使用している場合は、最新バージョン(Docker Engine 29.8.2以降)へアップデートを適用してください。
■ 参考情報
- https://github.com/moby/moby/security/advisories/GHSA-7cfq-22r6-qp73
対応優先度: 高
対応期限: 速やかに
お疲れさまです。Docker Engineの脆弱性に関する情報共有です。
■ 概要
DNSレスポンスの処理不備により、コンテナイメージレジストリへの接続が侵害される脆弱性が報告されました。認証情報の漏洩や、悪意のあるイメージへの差し替えが行われるリスクがあります。
■ 影響範囲
- Docker Engine: 29.8.2 未満
- Moby (Go module): v2.0.0-beta.25 未満
■ 対応手順
1. 利用中のDocker EngineおよびMobyのバージョンを確認してください。
2. 脆弱なバージョンを使用している場合は、最新バージョン(Docker Engine 29.8.2以降)へアップデートを適用してください。
■ 参考情報
- https://github.com/moby/moby/security/advisories/GHSA-7cfq-22r6-qp73
対応優先度: 高
対応期限: 速やかに
Subject: [Security Advisory] Docker Engine CVE-2026-92543 Mitigation
Dear IT/Security Team,
We are sharing information regarding a high-severity vulnerability in Docker Engine.
■ Overview
Due to incorrect handling of DNS responses, a vulnerability exists that could allow an attacker to compromise connections to container image registries. This may lead to the exposure of authentication credentials or the substitution of legitimate images with malicious ones.
■ Affected Scope
- Docker Engine: versions prior to 29.8.2
- Moby (Go module): versions prior to v2.0.0-beta.25
■ Mitigation Steps
1. Verify the current version of Docker Engine and Moby in your environment.
2. Update to Docker Engine 29.8.2 or later to resolve the vulnerability.
■ Reference
- https://github.com/moby/moby/security/advisories/GHSA-7cfq-22r6-qp73
Priority: High
Deadline: Immediate
Dear IT/Security Team,
We are sharing information regarding a high-severity vulnerability in Docker Engine.
■ Overview
Due to incorrect handling of DNS responses, a vulnerability exists that could allow an attacker to compromise connections to container image registries. This may lead to the exposure of authentication credentials or the substitution of legitimate images with malicious ones.
■ Affected Scope
- Docker Engine: versions prior to 29.8.2
- Moby (Go module): versions prior to v2.0.0-beta.25
■ Mitigation Steps
1. Verify the current version of Docker Engine and Moby in your environment.
2. Update to Docker Engine 29.8.2 or later to resolve the vulnerability.
■ Reference
- https://github.com/moby/moby/security/advisories/GHSA-7cfq-22r6-qp73
Priority: High
Deadline: Immediate