Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-25153

Опубликовано: 15 фев. 2023
Источник: redhat
CVSS3: 5.5

Описание

containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file where a limit was not applied could cause a denial of service. This bug has been fixed in containerd 1.6.18 and 1.5.18. Users should update to these versions to resolve the issue. As a workaround, ensure that only trusted images are used and that only trusted users have permissions to import images.

A flaw was found in containerd. When importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file, where a limit was not applied could cause a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 6grafanaAffected
Red Hat Ceph Storage 6promtailAffected
Red Hat Ceph Storage 7grafanaAffected
Red Hat Ceph Storage 7promtailAffected
Red Hat Ceph Storage 8grafanaAffected
Red Hat Ceph Storage 8promtailAffected
Red Hat Ceph Storage 9.0cephFixedRHSA-2026:153629.01.2026
Red Hat Ceph Storage 9.0cephFixedRHSA-2026:153629.01.2026
RHEL-9-CNV-4.14container-native-virtualization/multus-dynamic-networks-rhel9FixedRHSA-2023:681708.11.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2174473containerd: OCI image importer memory exhaustion

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.2
ubuntu
около 3 лет назад

containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file where a limit was not applied could cause a denial of service. This bug has been fixed in containerd 1.6.18 and 1.5.18. Users should update to these versions to resolve the issue. As a workaround, ensure that only trusted images are used and that only trusted users have permissions to import images.

CVSS3: 6.2
nvd
около 3 лет назад

containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file where a limit was not applied could cause a denial of service. This bug has been fixed in containerd 1.6.18 and 1.5.18. Users should update to these versions to resolve the issue. As a workaround, ensure that only trusted images are used and that only trusted users have permissions to import images.

CVSS3: 5.5
msrc
около 3 лет назад

Описание отсутствует

CVSS3: 6.2
debian
около 3 лет назад

containerd is an open source container runtime. Before versions 1.6.18 ...

CVSS3: 5.5
github
около 3 лет назад

OCI image importer memory exhaustion in github.com/containerd/containerd

5.5 Medium

CVSS3