Affected by GO-2022-0390
and 9 other vulnerabilities
GO-2022-0390: Moby (Docker Engine) started with non-empty inheritable Linux process capabilities in github.com/docker/docker
GO-2022-0985: Docker supplementary group permissions not set up properly, allowing attackers to bypass primary group restrictions in github.com/docker/docker
GO-2022-1107: Container build can leak any path on the host into the container in github.com/docker/docker
GO-2024-2914: Moby (Docker Engine) is vulnerable to Ambiguous OCI manifest parsing in github.com/docker/docker
GO-2025-3829: Moby firewalld reload removes bridge network isolation in github.com/docker/docker
GO-2026-4883: Moby has an Off-by-one error in its plugin privilege validation in github.com/docker/docker
GO-2026-4887: Moby has AuthZ plugin bypass when provided oversized request bodies in github.com/docker/docker
GO-2026-5617: Docker: Race condition in docker cp allows bind mount redirection to host path in github.com/docker/docker
GO-2026-5668: Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap in github.com/docker/docker
GO-2026-5746: Docker: `PUT /containers/{id}/archive` executes container binary on the host in github.com/docker/docker
VolumeDataPathName is the name of the directory where the volume data is stored.
It uses a very distintive name to avoid collisions migrating data between
Docker versions.
type Root struct {
// contains filtered or unexported fields
}
Root implements the Driver interface for the volume package and
manages the creation/removal of volumes. It uses only standard vfs
commands to create/remove dirs within its provided scope.
New instantiates a new Root instance with the provided scope. Scope
is the base path that the Root instance uses to store its
volumes. The base path is created here if it does not exist.
Remove removes the specified volume and all underlying data. If the
given volume does not belong to this driver and an error is
returned. The volume is reference counted, if all references are
not released then the volume is not removed.