containerd containerd是containerd团队的一款容器运行环境软件。 containerd存在输入验证错误漏洞,该漏洞源于CRI plugin在从镜像配置传播标签到容器时未经验证,可能导致通过使用容器标签的插件在主机上执行任意命令。以下版本受到影响:1.7.33之前版本、2.0.0版本至2.0.10之前版本、2.1.0版本至2.1.9之前版本、2.2.0版本至2.2.5之前版本、2.3.0版本至2.3.2之前版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| containerd | containerd | < 1.7.33 |
affected |
>= 2.0.0, < 2.0.10 |
affected | ||
>= 2.1.0, < 2.1.9 |
affected | ||
>= 2.2.0, < 2.2.5 |
affected | ||
>= 2.3.0, < 2.3.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| containerd | containerd | < 1.7.33 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53489 | containerd: Arbitrary host CRI log file read via symlink following in CRI checkpoint resto | |
| CVE-2026-53492 | containerd CRI checkpoint restore CDI annotation smuggling | |
| CVE-2026-47262 | containerd image-triggered runtime DoS via unbounded group parsing | |
| CVE-2026-50195 | containerd: CRI checkpoint import allows local image tag poisoning | |
| CVE-2026-46680 | containerd user ID handling bypass allows runAsNonRoot evasion |
No comments yet