CVE-2025-47291
- EPSS 0.11%
- Veröffentlicht 21.05.2025 17:26:31
- Zuletzt bearbeitet 19.09.2025 17:25:42
containerd is an open-source container runtime. A bug was found in the containerd's CRI implementation where containerd, starting in version 2.0.1 and prior to version 2.0.5, doesn't put usernamespaced containers under the Kubernetes' cgroup hierarch...
CVE-2025-47290
- EPSS 0.01%
- Veröffentlicht 20.05.2025 18:25:51
- Zuletzt bearbeitet 19.09.2025 17:28:20
containerd is a container runtime. A time-of-check to time-of-use (TOCTOU) vulnerability was found in containerd v2.1.0. While unpacking an image during an image pull, specially crafted container images could arbitrarily modify the host file system. ...
CVE-2024-40635
- EPSS 0.01%
- Veröffentlicht 17.03.2025 21:32:37
- Zuletzt bearbeitet 02.10.2025 01:51:43
containerd is an open-source container runtime. A bug was found in containerd prior to versions 1.6.38, 1.7.27, and 2.0.4 where containers launched with a User set as a `UID:GID` larger than the maximum 32-bit signed integer can cause an overflow con...
CVE-2023-25173
- EPSS 0.02%
- Veröffentlicht 16.02.2023 15:15:20
- Zuletzt bearbeitet 21.11.2024 07:49:15
containerd is an open source container runtime. A bug was found in containerd prior to versions 1.6.18 and 1.5.18 where supplementary groups are not set up properly inside a container. If an attacker has direct access to a container and manipulates t...
CVE-2023-25153
- EPSS 0.13%
- Veröffentlicht 16.02.2023 15:15:19
- Zuletzt bearbeitet 21.11.2024 07:49:12
containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file where a limit was not appl...
CVE-2022-23471
- EPSS 0.23%
- Veröffentlicht 07.12.2022 23:15:09
- Zuletzt bearbeitet 21.11.2024 06:48:37
containerd is an open source container runtime. A bug was found in containerd's CRI implementation where a user can exhaust memory on the host. In the CRI stream server, a goroutine is launched to handle terminal resize events if a TTY is requested. ...
CVE-2022-31030
- EPSS 0.11%
- Veröffentlicht 09.06.2022 14:15:08
- Zuletzt bearbeitet 21.11.2024 07:03:44
containerd is an open source container runtime. A bug was found in the containerd's CRI implementation where programs inside a container can cause the containerd daemon to consume memory without bound during invocation of the `ExecSync` API. This can...
CVE-2022-23648
- EPSS 6.3%
- Veröffentlicht 03.03.2022 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:49:00
containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.14.12 where containers launched through containerd’s CRI implementation on Linux with a specially-craf...
CVE-2021-43816
- EPSS 0.15%
- Veröffentlicht 05.01.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:29:51
containerd is an open source container runtime. On installations using SELinux, such as EL8 (CentOS, RHEL), Fedora, or SUSE MicroOS, with containerd since v1.5.0-beta.0 as the backing container runtime interface (CRI), an unprivileged pod scheduled t...
CVE-2021-41103
- EPSS 0.07%
- Veröffentlicht 04.10.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:25:28
containerd is an open source container runtime with an emphasis on simplicity, robustness and portability. A bug was found in containerd where container root directories and some plugins had insufficiently restricted permissions, allowing otherwise u...