CVE-2025-36356·Docker vulnerability
IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authenticated user to escalate their privileges to root due to execution with more privileges than required.
- Severity
- critical
- Software
- Docker
- Fixed in
- 11.0.1.0
- Published
- 2025-10-06
Affected versions
From: 11.0.0.0
Until: 11.0.1.0
Fixed in: 11.0.1.0
How to fix this CVE
Docker users running IBM Security Verify Access versions 11.0.0.0 through 11.0.1.0 must upgrade to the patched release immediately, as local users can exploit privilege escalation to gain root-level access. Review your deployment architecture to ensure Docker is running with minimal required privileges and audit any recent local account activity for signs of unauthorized escalation attempts.
sudo dnf update docker-ceDefensia detects this vulnerability
How to check if you are affected
- Run `docker --version` and check if the version falls within 11.0.0.0 to 11.0.1.0 range
- Execute `docker ps --all` to enumerate running containers and verify they are not running with unnecessary elevated privileges (check for --privileged flag or capability grants)
- Search system audit logs with `sudo ausearch -m execve | grep -i docker` to identify unauthorized privilege escalation attempts targeting Docker socket or daemon processes
- Confirm patch application by running `docker --version` again and verifying the version is above 11.0.1.0
FAQ
What is CVE-2025-36356?
CVE-2025-36356 is a critical local privilege escalation vulnerability in Docker versions 11.0.0.0 through 11.0.1.0 that allows authenticated local users to escalate privileges to root by exploiting overly permissive process execution contexts within the Docker daemon.
Is CVE-2025-36356 being actively exploited?
No, CVE-2025-36356 is not currently listed on the CISA Known Exploited Vulnerabilities catalog and no public exploits have been disclosed, but the critical CVSS score of 9.3 warrants immediate patching.
What versions of Docker are affected by CVE-2025-36356?
IBM Security Verify Access Docker versions 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 are vulnerable; standard Docker installations are not affected unless running IBM Security Verify Access components.
How do I check if my server is vulnerable to CVE-2025-36356?
Run `docker --version` and if it reports a version between 11.0.0.0 and 11.0.1.0, your system is vulnerable and requires immediate upgrade to 11.0.1.0 or later.
Does Defensia detect CVE-2025-36356?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Docker is installed on a monitored server, CVE-2025-36356 will appear in your dashboard with remediation steps.
Related Docker CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-36356. Free for 1 server.
Get started free