containerd containerd是containerd团队的一款容器运行环境软件。 containerd存在安全漏洞,该漏洞源于CRI检查点导入过程中未能正确验证检查点镜像配置中的镜像引用,可能导致具有创建Pod权限的攻击者使用特制检查点镜像强制containerd拉取恶意镜像并分配任意本地标签,从而投毒节点本地镜像缓存,导致其他Pod无意中执行恶意镜像,进而导致受影响的Pod被破解,允许攻击者在受害Pod身份下执行任意代码。以下版本受到影响:2.3.2之前版本、2.2.5之前版本和2.1.9之
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| containerd | containerd | >= 2.1.0, < 2.1.9 |
affected |
>= 2.2.0, < 2.2.5 |
affected | ||
>= 2.3.0, < 2.3.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| containerd | containerd | >= 2.1.0, < 2.1.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53488 | containerd CRI plugin: — image-config `LABEL` flows to restart-monitor `binary://` logger: | |
| CVE-2026-53489 | containerd: Arbitrary host CRI log file read via symlink following in CRI checkpoint resto | |
| CVE-2026-53492 | containerd CRI checkpoint restore CDI annotation smuggling | |
| CVE-2026-47262 | containerd image-triggered runtime DoS via unbounded group parsing | |
| CVE-2026-46680 | containerd user ID handling bypass allows runAsNonRoot evasion |
No comments yet