Database/Container, Kubernetes & orchestration
containerd: Crafted image config allows arbitrary host file read by containers launched via the CRI plugin
Impact
Crafted image config allows arbitrary host file read by containers launched via the CRI plugin
Who can reach it
Malicious image
What to do
Rolling containerd upgrade with node drain
Fleet impact
How widespread
Universal - containerd is the runtime under nearly every Kubernetes-based GPU cloud; affects <1.6.1 / 1.5.10 / 1.4.12
Cost to remediate
daemon-restart - containerd upgrade; with --restart semantics containers may survive, but the fleet-wide rollout still means touching every node
Why it hits the whole fleet
A specially crafted *image config* - i.e. something a customer supplies - mounts read-only copies of arbitrary host files into the container, bypassing Pod Security Policy; any tenant who can push an image reads host secrets on every node they land on
References
Related entries
- containerd: Overly broad default permissions on containerd-managed directoriesCVE-2024-25621 · containerdHigh
- containerd: Numeric User directive that fails 32-bit parsing is treated as a username, changing the effective UIDCVE-2026-46680 · containerdHigh
- containerd: CRI Attach implementation bug lets a user attach to a container they should not reachCVE-2025-64329 · containerdMedium
- containerd: Environment variables from an unrelated image leak into a container, exposing another tenant's secretsCVE-2021-21334 · containerdMedium
- containerd: Unbounded read on OCI image import causes containerd OOMCVE-2023-25153 · containerdMedium
- containerd: "ContainerDrip": registry credentials leaked to an attacker-controlled URL referenced in an image manifestCVE-2020-15157 · containerdMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.