Linuxfoundation

Containerd

14 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.11%
  • Veröffentlicht 21.05.2025 17:26:31
  • Zuletzt bearbeitet 19.09.2025 17:25:42

containerd is an open-source container runtime. A bug was found in the containerd's CRI implementation where containerd, starting in version 2.0.1 and prior to version 2.0.5, doesn't put usernamespaced containers under the Kubernetes' cgroup hierarch...

  • EPSS 0.01%
  • Veröffentlicht 20.05.2025 18:25:51
  • Zuletzt bearbeitet 19.09.2025 17:28:20

containerd is a container runtime. A time-of-check to time-of-use (TOCTOU) vulnerability was found in containerd v2.1.0. While unpacking an image during an image pull, specially crafted container images could arbitrarily modify the host file system. ...

  • EPSS 0.01%
  • Veröffentlicht 17.03.2025 21:32:37
  • Zuletzt bearbeitet 02.10.2025 01:51:43

containerd is an open-source container runtime. A bug was found in containerd prior to versions 1.6.38, 1.7.27, and 2.0.4 where containers launched with a User set as a `UID:GID` larger than the maximum 32-bit signed integer can cause an overflow con...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 16.02.2023 15:15:20
  • Zuletzt bearbeitet 21.11.2024 07:49:15

containerd is an open source container runtime. A bug was found in containerd prior to versions 1.6.18 and 1.5.18 where supplementary groups are not set up properly inside a container. If an attacker has direct access to a container and manipulates t...

  • EPSS 0.13%
  • Veröffentlicht 16.02.2023 15:15:19
  • Zuletzt bearbeitet 21.11.2024 07:49:12

containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file where a limit was not appl...

  • EPSS 0.23%
  • Veröffentlicht 07.12.2022 23:15:09
  • Zuletzt bearbeitet 21.11.2024 06:48:37

containerd is an open source container runtime. A bug was found in containerd's CRI implementation where a user can exhaust memory on the host. In the CRI stream server, a goroutine is launched to handle terminal resize events if a TTY is requested. ...

  • EPSS 0.11%
  • Veröffentlicht 09.06.2022 14:15:08
  • Zuletzt bearbeitet 21.11.2024 07:03:44

containerd is an open source container runtime. A bug was found in the containerd's CRI implementation where programs inside a container can cause the containerd daemon to consume memory without bound during invocation of the `ExecSync` API. This can...

Exploit
  • EPSS 6.3%
  • Veröffentlicht 03.03.2022 14:15:07
  • Zuletzt bearbeitet 21.11.2024 06:49:00

containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.14.12 where containers launched through containerd’s CRI implementation on Linux with a specially-craf...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 05.01.2022 19:15:08
  • Zuletzt bearbeitet 21.11.2024 06:29:51

containerd is an open source container runtime. On installations using SELinux, such as EL8 (CentOS, RHEL), Fedora, or SUSE MicroOS, with containerd since v1.5.0-beta.0 as the backing container runtime interface (CRI), an unprivileged pod scheduled t...

  • EPSS 0.07%
  • Veröffentlicht 04.10.2021 17:15:08
  • Zuletzt bearbeitet 21.11.2024 06:25:28

containerd is an open source container runtime with an emphasis on simplicity, robustness and portability. A bug was found in containerd where container root directories and some plugins had insufficiently restricted permissions, allowing otherwise u...