Описание
containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4, and 2.2.0-beta.0 through 2.2.0-rc.1 contain a bug in the CRI Attach implementation where a user can exhaust memory on the host due to goroutine leaks. This issue is fixed in versions 1.7.29, 2.0.7, 2.1.5 and 2.2.0. To workaround this vulnerability, users can set up an admission controller to control accesses to pods/attach resources.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 1.7.24~ds1-10ubuntu1 |
| esm-apps/bionic | released | 1.6.12-0ubuntu1~18.04.1+esm3 |
| esm-apps/noble | released | 1.6.24~ds1-1ubuntu1.3+esm2 |
| esm-apps/xenial | released | 1.2.6-0ubuntu1~16.04.6+esm6 |
| esm-infra/focal | released | 1.6.12-0ubuntu1~20.04.8+esm1 |
| jammy | released | 1.6.12-0ubuntu1~22.04.10 |
| noble | needed | |
| plucky | ignored | end of life, was needs-triage |
| questing | released | 1.7.24~ds1-8ubuntu1.1 |
| upstream | needs-triage |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 2.2.1-0ubuntu1 |
| esm-apps/focal | released | 1.7.24-0ubuntu1~20.04.2+esm1 |
| esm-apps/jammy | released | 1.7.28-0ubuntu1~22.04.1+esm1 |
| jammy | needed | |
| noble | released | 1.7.28-0ubuntu1~24.04.2 |
| plucky | ignored | end of life, was needs-triage |
| questing | released | 2.1.3-0ubuntu3.1 |
| upstream | needs-triage |
Показывать по
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4, and 2.2.0-beta.0 through 2.2.0-rc.1 contain a bug in the CRI Attach implementation where a user can exhaust memory on the host due to goroutine leaks. This issue is fixed in versions 1.7.29, 2.0.7, 2.1.5 and 2.2.0. To workaround this vulnerability, users can set up an admission controller to control accesses to pods/attach resources.
containerd CRI server: Host memory exhaustion through Attach goroutine leak
containerd is an open-source container runtime. Versions 1.7.28 and be ...
containerd CRI server: Host memory exhaustion through Attach goroutine leak
Уязвимость среды выполнения контейнеров containerd, связанная с отсутствием освобождения памяти после эффективного срока службы, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
5.5 Medium
CVSS3