Linuxfoundation
Linuxfoundation Containerd: vulnerabilidades y CVE
Linuxfoundation Containerd tiene 24 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE24
Últimos 12 meses10
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-53493 | Media (6.9) | 0.36% | — | 25 sept 2026 | containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI index graph can force very high CPU/memory usage during PullImage (before container start),… |
| CVE-2026-53495 | Media (6.8) | 0.16% | — | 14 sept 2026 | containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine in… |
| CVE-2026-53492 | Alta (8.4) | 0.35% | — | 1 jul 2026 | containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint image… |
| CVE-2026-53489 | Alta (8.2) | 0.17% | — | 1 jul 2026 | containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a bug where the CRI plugin restores container.log from a checkpoint image without validating a symlinked path. This could… |
| CVE-2026-50195 | Media (5.6) | 0.30% | — | 1 jul 2026 | containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the CRI checkpoint import process where it fails to validate the image references specified within a… |
| CVE-2026-47262 | Media (5.3) | 0.27% | — | 1 jul 2026 | containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vulnerability that allows a maliciously crafted image to cause a Denial of Service (DoS) condition.… |
| CVE-2026-46680 | Alta (7.3) | 0.16% | — | 1 jul 2026 | containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as… |
| CVE-2026-53488 | Crítica (9.4) | 0.16% | — | 1 jul 2026 | containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without… |
| CVE-2025-64329 | Media (6.9) | 0.16% | — | 7 nov 2025 | containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4, and 2.2.0-beta.0 through 2.2.0-rc.1 contain a bug in the CRI Attach implementation where… |
| CVE-2024-25621 | Alta (7.8) | 0.16% | — | 6 nov 2025 | containerd is an open-source container runtime. Versions 0.1.0 through 1.7.28, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4 and 2.2.0-beta.0 through 2.2.0-rc.1 have an overly broad default permission… |
| CVE-2025-47291 | Media (4.6) | 0.28% | — | 21 may 2025 | containerd is an open-source container runtime. A bug was found in the containerd's CRI implementation where containerd, starting in version 2.0.1 and prior to version 2.0.5, doesn't put usernamespaced containers under… |
| CVE-2025-47290 | Alta (7.6) | 0.50% | — | 20 may 2025 | containerd is a container runtime. A time-of-check to time-of-use (TOCTOU) vulnerability was found in containerd v2.1.0. While unpacking an image during an image pull, specially crafted container images could… |
| CVE-2024-40635 | Alta (7.8) | 0.29% | — | 17 mar 2025 | containerd is an open-source container runtime. A bug was found in containerd prior to versions 1.6.38, 1.7.27, and 2.0.4 where containers launched with a User set as a `UID:GID` larger than the maximum 32-bit signed… |
| CVE-2023-25173 | Alta (7.8) | 0.54% | — | 16 feb 2023 | containerd is an open source container runtime. A bug was found in containerd prior to versions 1.6.18 and 1.5.18 where supplementary groups are not set up properly inside a container. If an attacker has direct access… |
| CVE-2023-25153 | Media (5.5) | 0.36% | — | 16 feb 2023 | containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large… |
| CVE-2022-23471 | Media (6.5) | 1.1% | — | 7 dic 2022 | containerd is an open source container runtime. A bug was found in containerd's CRI implementation where a user can exhaust memory on the host. In the CRI stream server, a goroutine is launched to handle terminal resize… |
| CVE-2022-31030 | Media (5.5) | 0.38% | — | 9 jun 2022 | containerd is an open source container runtime. A bug was found in the containerd's CRI implementation where programs inside a container can cause the containerd daemon to consume memory without bound during invocation… |
| CVE-2022-23648 | Alta (7.5) | 27% | — | 3 mar 2022 | containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.14.12 where containers launched through containerd’s CRI implementation… |
| CVE-2021-43816 | Crítica (9.1) | 1.7% | — | 5 ene 2022 | containerd is an open source container runtime. On installations using SELinux, such as EL8 (CentOS, RHEL), Fedora, or SUSE MicroOS, with containerd since v1.5.0-beta.0 as the backing container runtime interface (CRI),… |
| CVE-2021-41103 | Alta (7.8) | 0.52% | — | 4 oct 2021 | containerd is an open source container runtime with an emphasis on simplicity, robustness and portability. A bug was found in containerd where container root directories and some plugins had insufficiently restricted… |
| CVE-2021-32760 | Media (6.3) | 1.6% | — | 19 jul 2021 | containerd is a container runtime. A bug was found in containerd versions prior to 1.4.8 and 1.5.4 where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing… |
| CVE-2021-21334 | Media (6.3) | 2.0% | — | 10 mar 2021 | In containerd (an industry-standard container runtime) before versions 1.3.10 and 1.4.4, containers launched through containerd's CRI implementation (through Kubernetes, crictl, or any other pod/container client that… |
| CVE-2020-15257 | Media (5.2) | 3.2% | — | 1 dic 2020 | containerd is an industry-standard container runtime and is available as a daemon for Linux and Windows. In containerd before versions 1.3.9 and 1.4.3, the containerd-shim API is improperly exposed to host network… |
| CVE-2020-15157 | Media (6.1) | 2.3% | — | 16 oct 2020 | In containerd (an industry-standard container runtime) before version 1.2.14 there is a credential leaking vulnerability. If a container image manifest in the OCI Image format or Docker Image V2 Schema 2 format includes… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.