containerd containerd是containerd团队的一款容器运行环境软件。 containerd 2.3.2之前版本、2.2.5之前版本和2.1.9之前版本存在安全漏洞,该漏洞源于CRI实现不当信任容器恢复期间来自不受信任检查点镜像元数据中的Container Device Interface注释,可能导致具有Pod创建权限的用户绕过标准Kubernetes资源分配和设备插件执行,向恢复的容器中注入任意CDI编辑内容。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| containerd | containerd | >= 2.1.0, < 2.1.9 |
affected |
>= 2.2.0, < 2.2.5 |
affected | ||
>= 2.3.0, < 2.3.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| containerd | containerd | >= 2.1.0, < 2.1.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53488 | containerd CRI plugin: — image-config `LABEL` flows to restart-monitor `binary://` logger: | |
| CVE-2026-53489 | containerd: Arbitrary host CRI log file read via symlink following in CRI checkpoint resto | |
| CVE-2026-47262 | containerd image-triggered runtime DoS via unbounded group parsing | |
| CVE-2026-50195 | containerd: CRI checkpoint import allows local image tag poisoning | |
| CVE-2026-46680 | containerd user ID handling bypass allows runAsNonRoot evasion |
No comments yet