containerd containerd是containerd团队的一款容器运行环境软件。 containerd 2.3.2之前版本、2.2.5之前版本和2.1.9之前版本存在后置链接漏洞,该漏洞源于CRI plugin从检查点镜像恢复container.log时未验证符号链接路径,可能导致通过kubectl logs读取主机上的任意文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| containerd | containerd | >= 2.1.0, < 2.1.9 |
affected |
>= 2.2.0, < 2.2.5 |
affected | ||
>= 2.3.0, < 2.3.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| containerd | containerd | >= 2.1.0, < 2.1.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53488 | containerd CRI plugin: — image-config `LABEL` flows to restart-monitor `binary://` logger: | |
| CVE-2026-53492 | containerd CRI checkpoint restore CDI annotation smuggling | |
| CVE-2026-47262 | containerd image-triggered runtime DoS via unbounded group parsing | |
| CVE-2026-50195 | containerd: CRI checkpoint import allows local image tag poisoning | |
| CVE-2026-46680 | containerd user ID handling bypass allows runAsNonRoot evasion |
No comments yet