Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 9

Количество 9

fstec логотип

BDU:2026-09648

2 месяца назад

Уязвимость среды выполнения контейнеров containerd, связанная с небезопасным управлением привилегиями, позволяющая нарушителю обойти существующие ограничения безопасности или повысить свои привилегии

CVSS3: 7.8
EPSS: Низкий
redos логотип

ROS-20260626-73-0016

около 1 месяца назад

Уязвимость containerd

CVSS3: 8.4
EPSS: Низкий
ubuntu логотип

CVE-2026-46680

около 1 месяца назад

containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2026-46680

около 1 месяца назад

containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-46680

около 1 месяца назад

containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2026-46680

около 1 месяца назад

containerd is an open-source container runtime. In versions prior to 1 ...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-fqw6-gf59-qr4w

2 месяца назад

containerd user ID handling bypass allows runAsNonRoot evasion

CVSS3: 7.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21072-1

около 1 месяца назад

Security update for trivy

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21213-1

около 1 месяца назад

Security update for containerd

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-09648

Уязвимость среды выполнения контейнеров containerd, связанная с небезопасным управлением привилегиями, позволяющая нарушителю обойти существующие ограничения безопасности или повысить свои привилегии

CVSS3: 7.8
0%
Низкий
2 месяца назад
redos логотип
ROS-20260626-73-0016

Уязвимость containerd

CVSS3: 8.4
0%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2026-46680

containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-46680

containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-46680

containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-46680

containerd is an open-source container runtime. In versions prior to 1 ...

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-fqw6-gf59-qr4w

containerd user ID handling bypass allows runAsNonRoot evasion

CVSS3: 7.8
0%
Низкий
2 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21072-1

Security update for trivy

около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21213-1

Security update for containerd

около 1 месяца назад

Уязвимостей на страницу