Количество 9
Количество 9
GHSA-fqw6-gf59-qr4w
containerd user ID handling bypass allows runAsNonRoot evasion
CVE-2026-46680
containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1.
CVE-2026-46680
containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1.
CVE-2026-46680
containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1.
CVE-2026-46680
containerd is an open-source container runtime. In versions prior to 1 ...
BDU:2026-09648
Уязвимость среды выполнения контейнеров containerd, связанная с небезопасным управлением привилегиями, позволяющая нарушителю обойти существующие ограничения безопасности или повысить свои привилегии
ROS-20260626-73-0016
Уязвимость containerd
openSUSE-SU-2026:21072-1
Security update for trivy
openSUSE-SU-2026:21213-1
Security update for containerd
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-fqw6-gf59-qr4w containerd user ID handling bypass allows runAsNonRoot evasion | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-46680 containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1. | CVSS3: 7.8 | 0% Низкий | около 1 месяца назад | |
CVE-2026-46680 containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1. | CVSS3: 7.8 | 0% Низкий | около 1 месяца назад | |
CVE-2026-46680 containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1. | CVSS3: 7.8 | 0% Низкий | около 1 месяца назад | |
CVE-2026-46680 containerd is an open-source container runtime. In versions prior to 1 ... | CVSS3: 7.8 | 0% Низкий | около 1 месяца назад | |
BDU:2026-09648 Уязвимость среды выполнения контейнеров containerd, связанная с небезопасным управлением привилегиями, позволяющая нарушителю обойти существующие ограничения безопасности или повысить свои привилегии | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
ROS-20260626-73-0016 Уязвимость containerd | CVSS3: 8.4 | 0% Низкий | около 1 месяца назад | |
openSUSE-SU-2026:21072-1 Security update for trivy | около 1 месяца назад | |||
openSUSE-SU-2026:21213-1 Security update for containerd | около 1 месяца назад |
Уязвимостей на страницу