Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-53489

Опубликовано: 01 июл. 2026
Источник: ubuntu
Приоритет: high
CVSS3: 6.5

Описание

containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a bug where the CRI plugin restores container.log from a checkpoint image without validating a symlinked path. This could result in reading an arbitrary file on the host via kubectl logs. This issue has been fixed in versions 2.3.2, 2.2.5 and 2.1.9.

РелизСтатусПримечание
devel

not-affected

code not present
esm-apps-legacy/xenial

not-affected

code not present
esm-apps/bionic

not-affected

code not present
esm-apps/noble

not-affected

code not present
esm-apps/resolute

not-affected

code not present
esm-infra/focal

not-affected

code not present
jammy

not-affected

code not present
noble

not-affected

code not present
questing

not-affected

code not present
resolute

not-affected

code not present

Показывать по

РелизСтатусПримечание
devel

not-affected

2.2.2-0ubuntu2
esm-apps/focal

not-affected

code not present
esm-apps/jammy

released

2.2.1-0ubuntu1~22.04.2
jammy

released

2.2.1-0ubuntu1~22.04.2
noble

released

2.2.1-0ubuntu1~24.04.3
questing

released

2.2.1-0ubuntu1~25.10.2
resolute

released

2.2.2-0ubuntu1.1
upstream

released

2.2.5

Показывать по

РелизСтатусПримечание
devel

not-affected

2.2.2-0ubuntu2
jammy

DNE

noble

DNE

questing

released

2.1.6-0ubuntu1~25.10.2
resolute

released

2.2.2-0ubuntu1.1
upstream

released

2.2.5

Показывать по

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
около 1 месяца назад

containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a bug where the CRI plugin restores container.log from a checkpoint image without validating a symlinked path. This could result in reading an arbitrary file on the host via kubectl logs. This issue has been fixed in versions 2.3.2, 2.2.5 and 2.1.9.

CVSS3: 6.5
nvd
около 1 месяца назад

containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a bug where the CRI plugin restores container.log from a checkpoint image without validating a symlinked path. This could result in reading an arbitrary file on the host via kubectl logs. This issue has been fixed in versions 2.3.2, 2.2.5 and 2.1.9.

CVSS3: 6.5
debian
около 1 месяца назад

containerd is an open-source container runtime. Versions prior to 2.3. ...

github
около 2 месяцев назад

Arbitrary host CRI log file read via symlink following in CRI checkpoint restore

suse-cvrf
около 1 месяца назад

Security update for trivy

6.5 Medium

CVSS3