PT-2021-6093 · Unknown+7 · Kubernetes Containerd+6
Mcgowan
·
Published
2021-10-04
·
Updated
2025-10-11
·
CVE-2021-41103
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
containerd versions prior to 1.4.11
containerd versions prior to 1.5.7
Description
A bug was found in containerd where container root directories and some plugins had insufficiently restricted permissions, allowing otherwise unprivileged Linux users to traverse directory contents and execute programs. When containers included executable programs with extended permission bits (such as setuid), unprivileged Linux users could discover and execute those programs. When the UID of an unprivileged Linux user on the host collided with the file owner or group inside a container, the unprivileged Linux user on the host could discover, read, and modify those files.
Recommendations
Update to containerd version 1.4.11 or later to fix the vulnerability.
Update to containerd version 1.5.7 or later to fix the vulnerability.
As a temporary workaround, consider restarting containers or updating directory permissions to mitigate the vulnerability.
Limit access to the host to trusted users.
Update directory permission on container bundles directories.
Exploit
Fix
Path traversal
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Kubernetes Containerd
Linuxmint
Red Os
Suse
Ubuntu