containerd containerd是containerd团队的一款容器运行环境软件。 containerd存在权限许可和访问控制问题漏洞,该漏洞源于对无法解析为32位整数的数字User指令错误地视为用户名,导致runAsNonRoot绕过,如果特制镜像提供/etc/passwd文件将大数字字符串映射到root,容器最终以root权限运行,可能导致绕过Kubernetes runAsNonRoot限制。以下版本受到影响:1.7.32之前版本、2.0.9之前版本、2.2.4之前版本和2.3.1之前版本
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| containerd | containerd | < 1.7.32 |
affected |
>= 2.0.4, < 2.0.9 |
affected | ||
>= 2.0.10, < 2.2.4 |
affected | ||
>= 2.2.5, < 2.3.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| containerd | containerd | < 1.7.32 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53488 | containerd CRI plugin: — image-config `LABEL` flows to restart-monitor `binary://` logger: | |
| CVE-2026-53489 | containerd: Arbitrary host CRI log file read via symlink following in CRI checkpoint resto | |
| CVE-2026-53492 | containerd CRI checkpoint restore CDI annotation smuggling | |
| CVE-2026-47262 | containerd image-triggered runtime DoS via unbounded group parsing | |
| CVE-2026-50195 | containerd: CRI checkpoint import allows local image tag poisoning |
No comments yet