Описание
containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | needed | |
| esm-apps-legacy/xenial | not-affected | code not present |
| esm-apps/bionic | released | 1.6.12-0ubuntu1~18.04.1+esm4 |
| esm-apps/noble | released | 1.6.24~ds1-1ubuntu1.3+esm3 |
| esm-apps/resolute | released | 1.7.24~ds1-10ubuntu1+esm1 |
| esm-infra/focal | released | 1.6.12-0ubuntu1~20.04.8+esm2 |
| jammy | released | 1.6.12-0ubuntu1~22.04.11 |
| noble | needed | |
| questing | ignored | end of life, was needed |
| resolute | needed |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 2.2.2-0ubuntu2 |
| esm-apps/focal | released | 1.7.24-0ubuntu1~20.04.2+esm2 |
| esm-apps/jammy | released | 2.2.1-0ubuntu1~22.04.2 |
| jammy | released | 2.2.1-0ubuntu1~22.04.2 |
| noble | released | 2.2.1-0ubuntu1~24.04.3 |
| questing | released | 2.2.1-0ubuntu1~25.10.2 |
| resolute | released | 2.2.2-0ubuntu1.1 |
| upstream | released | 2.2.5 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 2.2.2-0ubuntu2 |
| jammy | DNE | |
| noble | DNE | |
| questing | released | 2.1.6-0ubuntu1~25.10.2 |
| resolute | released | 2.2.2-0ubuntu1.1 |
| upstream | released | 2.2.5 |
Показывать по
EPSS
8.8 High
CVSS3
Связанные уязвимости
containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.
containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.
containerd is an open-source container runtime. In versions prior to 1 ...
containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull
EPSS
8.8 High
CVSS3