Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-46680

Опубликовано: 01 июл. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1.

A flaw was found in containerd, an open-source container runtime. Containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username. This vulnerability allows a crafted container image to bypass the Kubernetes runAsNonRoot restriction, potentially leading to privilege escalation where the container runs as the root user (UID 0). This can cause unexpected behavior in environments designed to enforce non-root user execution.

Отчет

Red Hat OpenShift Container Platform and its layered products include the containerd Go library as a build-time dependency for various components. These products do not use containerd as a container runtime; CRI-O is used instead. The vulnerable code path responsible for parsing User directives during container runtime spec generation is not exercised. Therefore, although the containerd library is present in shipped binaries, the vulnerability is not exploitable in the context of Red Hat products.

Меры по смягчению последствий

Enforce a specific numeric runAsUser in the Kubernetes Pod securityContext, which overrides the User directive in the container image and prevents the bypass. Additionally, restrict access to push container images to trusted users only, and validate image provenance before deployment.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2assisted/agent-preinstall-image-builder-rhel9Not affected
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-agent-rhel9Not affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-cloud-api-adaptor-rhel9Not affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-monitor-rhel9Not affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-must-gather-rhel9Not affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Not affected
Deployment Validation Operatordvo/deployment-validation-rhel8-operatorNot affected
Gatekeeper 3gatekeeper/gatekeeper-rhel9Not affected
Kernel Module Management Operator for Red Hat Openshiftkmm/kernel-module-management-must-gather-rhel9Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/cluster-logging-rhel9-operatorNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-681
https://bugzilla.redhat.com/show_bug.cgi?id=2496104github.com/containerd/containerd: containerd: Privilege escalation via incorrect user ID handling

EPSS

Процентиль: 13%
0.00221
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 1 месяца назад

containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1.

CVSS3: 7.8
nvd
около 1 месяца назад

containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1.

CVSS3: 7.8
debian
около 1 месяца назад

containerd is an open-source container runtime. In versions prior to 1 ...

CVSS3: 7.8
github
2 месяца назад

containerd user ID handling bypass allows runAsNonRoot evasion

CVSS3: 7.8
fstec
2 месяца назад

Уязвимость среды выполнения контейнеров containerd, связанная с небезопасным управлением привилегиями, позволяющая нарушителю обойти существующие ограничения безопасности или повысить свои привилегии

EPSS

Процентиль: 13%
0.00221
Низкий

7.8 High

CVSS3