PT-2023-1887 · Unknown+7 · Kubernetes Containerd+6
CVSS v2.0
6.8
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
containerd versions 1.6.17 and earlier, containerd versions 1.5.17 and earlier
Description
The issue is related to the import of OCI images in containerd, where there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file could cause a denial of service.
Recommendations
Update to containerd version 1.6.18 or later to resolve the issue.
Update to containerd version 1.5.18 or later to resolve the issue.
As a temporary workaround, ensure that only trusted images are used and that only trusted users have permissions to import images.
Exploit
Fix
DoS
Resource Exhaustion
Allocation of Resources Without Limits
Improper Privilege Management
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Kubernetes Containerd
Linuxmint
Red Os
Suse
Ubuntu