[HIGH] Patch docker-cli for CVE-2026-17106 - #18659
Conversation
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
|
@microsoft-github-policy-service agree company="Microsoft" |
|
Patch Analysis: Backported: Yes
Files NOT backported — and why
Verification Correctly scoped backport of the upstream containment fix; only the non-security RebaseArchiveEntries change and test files are omitted. No toolchain/build changes required on Azure Linux 3.0. Pipelines - Run PR-18659+docker-cli+unknown has been triggered and it has passed. Patch Application:
|
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |

Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-staticsubpackages, etc.) have had theirReleasetag incremented../cgmanifest.json,./toolkit/scripts/toolchain/cgmanifest.json,.github/workflows/cgmanifest.json)./LICENSES-AND-NOTICES/SPECS/data/licenses.json,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON)*.signatures.jsonfilessudo make go-tidy-allandsudo make go-test-coveragepassSummary
Patch docker-cli for CVE-2026-17106
Change Log
Does this affect the toolchain?
NO
Associated issues
Links to CVEs
Test Methodology
A) WITH patch (current HEAD) — expect PASS
Expected: --- PASS for SymlinkBreakout, RejectsRelativeEscapeBeforeAbsoluteSymlink, HardlinkThroughAbsoluteSymlink → ok.
B) WITHOUT patch (vulnerable) — expect FAIL
How the PoC works:
the tar defines inner/go_up → .. and inner/go_up/escape → ../victim, then writes inner/go_up/escape/newfile.