Database/Container, Kubernetes & orchestration
containerd: Crafted image can change Unix file permissions of existing host files during extraction
CVSS 5.0CVE-2021-32760Container, Kubernetes & orchestrationcurated
Impact
Crafted image can change Unix file permissions of existing host files during extraction
Who can reach it
Malicious image
What to do
Rolling containerd upgrade with node drain
References
Related entries
- containerd: UID:GID larger than 32-bit signed max wraps to 0, silently running the container as rootCVE-2024-40635 · containerdMedium
- containerd: User-namespaced containers not placed under the Kubernetes cgroup, defeating resource limitsCVE-2025-47291 · containerdMedium
- containerd: CRI plugin propagates unvalidated image LABEL values into container configCVE-2026-53488 · containerdCritical
- containerd: CRI trusts CDI annotations inside untrusted checkpoint image metadataCVE-2026-53492 · containerdHigh
- containerd: CRI restores container.log from a checkpoint image without validating symlinksCVE-2026-53489 · containerdHigh
- containerd: On SELinux hosts, an unprivileged pod with a hostPath volume can gain full read/write to the host filesystemCVE-2021-43816 · containerdHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.