Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-53488

Опубликовано: 01 июл. 2026
Источник: ubuntu
Приоритет: high
EPSS Низкий
CVSS3: 8.8

Описание

containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.

РелизСтатусПримечание
devel

needed

esm-apps-legacy/xenial

not-affected

code not present
esm-apps/bionic

released

1.6.12-0ubuntu1~18.04.1+esm4
esm-apps/noble

released

1.6.24~ds1-1ubuntu1.3+esm3
esm-apps/resolute

released

1.7.24~ds1-10ubuntu1+esm1
esm-infra/focal

released

1.6.12-0ubuntu1~20.04.8+esm2
jammy

released

1.6.12-0ubuntu1~22.04.11
noble

needed

questing

ignored

end of life, was needed
resolute

needed

Показывать по

РелизСтатусПримечание
devel

not-affected

2.2.2-0ubuntu2
esm-apps/focal

released

1.7.24-0ubuntu1~20.04.2+esm2
esm-apps/jammy

released

2.2.1-0ubuntu1~22.04.2
jammy

released

2.2.1-0ubuntu1~22.04.2
noble

released

2.2.1-0ubuntu1~24.04.3
questing

released

2.2.1-0ubuntu1~25.10.2
resolute

released

2.2.2-0ubuntu1.1
upstream

released

2.2.5

Показывать по

РелизСтатусПримечание
devel

not-affected

2.2.2-0ubuntu2
jammy

DNE

noble

DNE

questing

released

2.1.6-0ubuntu1~25.10.2
resolute

released

2.2.2-0ubuntu1.1
upstream

released

2.2.5

Показывать по

EPSS

Процентиль: 7%
0.00176
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
redhat
около 1 месяца назад

containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.

CVSS3: 8.8
nvd
около 1 месяца назад

containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.

CVSS3: 8.8
debian
около 1 месяца назад

containerd is an open-source container runtime. In versions prior to 1 ...

github
около 2 месяцев назад

containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull

suse-cvrf
около 1 месяца назад

Security update for trivy

EPSS

Процентиль: 7%
0.00176
Низкий

8.8 High

CVSS3