Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:4072-1

Опубликовано: 12 нояб. 2025
Источник: suse-cvrf

Описание

Security update for containerd

This update for containerd fixes the following issues:

  • Update to containerd v1.7.29
  • CVE-2024-25621: Fixed an overly broad default permission vulnerability. (bsc#1253126)
  • CVE-2025-64329: Fixed a goroutine leaks which can lead to memory exhaustion on the host. (bsc#1253132)

Список пакетов

SUSE Linux Enterprise Server 12 SP5-LTSS
containerd-1.7.29-16.105.1
containerd-ctr-1.7.29-16.105.1
containerd-devel-1.7.29-16.105.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
containerd-1.7.29-16.105.1
containerd-ctr-1.7.29-16.105.1
containerd-devel-1.7.29-16.105.1

Описание

containerd is an open-source container runtime. Versions 0.1.0 through 1.7.28, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4 and 2.2.0-beta.0 through 2.2.0-rc.1 have an overly broad default permission vulnerability. Directory paths `/var/lib/containerd`, `/run/containerd/io.containerd.grpc.v1.cri` and `/run/containerd/io.containerd.sandbox.controller.v1.shim` were all created with incorrect permissions. This issue is fixed in versions 1.7.29, 2.0.7, 2.1.5 and 2.2.0. Workarounds include updating system administrator permissions so the host can manually chmod the directories to not have group or world accessible permissions, or to run containerd in rootless mode.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:containerd-1.7.29-16.105.1
SUSE Linux Enterprise Server 12 SP5-LTSS:containerd-ctr-1.7.29-16.105.1
SUSE Linux Enterprise Server 12 SP5-LTSS:containerd-devel-1.7.29-16.105.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:containerd-1.7.29-16.105.1

Ссылки

Описание

containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4, and 2.2.0-beta.0 through 2.2.0-rc.1 contain a bug in the CRI Attach implementation where a user can exhaust memory on the host due to goroutine leaks. This issue is fixed in versions 1.7.29, 2.0.7, 2.1.5 and 2.2.0. To workaround this vulnerability, users can set up an admission controller to control accesses to pods/attach resources.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:containerd-1.7.29-16.105.1
SUSE Linux Enterprise Server 12 SP5-LTSS:containerd-ctr-1.7.29-16.105.1
SUSE Linux Enterprise Server 12 SP5-LTSS:containerd-devel-1.7.29-16.105.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:containerd-1.7.29-16.105.1

Ссылки