Intel

AIKIDO-2024-10009

github.com/containerd/containerd is vulnerable to Remote Code Execution (RCE)

Remote Code Execution (RCE)CVE-2024-21626 Published Jan 31, 2024

86

High Risk

This Affects:

Gogithub.com/containerd/containerd
1.0.0 - 1.6.27
Fixed in 1.6.28
1.7.0 - 1.7.12
Fixed in 1.7.13
Are you affected? Scan for Free

TL;DR

Affected versions of this library are vulnerable to container breakout, allowing attackers to escape the container's isolation.

Who does this affect?

You use containerd to run untrusted images.

Background info

github.com/containerd/containerd is vulnerable to Remote Code Execution (RCE) in versions 1.0.0 - 1.6.27 and 1.7.0 - 1.7.12.

How to fix this

Upgrade containerd to any of the patched versions

Links

Other