PT-2025-22285 · Unknown+1 · Kubernetes Containerd

Tõnis Tiigi

·

Published

2025-05-20

·

Updated

2025-09-19

·

CVE-2025-47290

CVSS v4.0

7.6

High

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U
Name of the Vulnerable Software and Affected Versions containerd version 2.1.0
Description A time-of-check to time-of-use (TOCTOU) vulnerability was found in containerd. This issue allows specially crafted container images to arbitrarily modify the host file system while unpacking an image during an image pull.
Recommendations For containerd version 2.1.0, update to version 2.1.1 to resolve the issue. As a temporary workaround, ensure that only trusted images are used and that only trusted users have permissions to import images.

Exploit

Fix

Time Of Check To Time Of Use

Weakness Enumeration

Related Identifiers

CVE-2025-47290
GHSA-CM76-QM8V-3J95
GO-2025-3699
OPENSUSE-SU-2025:15146-1
OPENSUSE-SU-2025:15159-1

Affected Products

Kubernetes Containerd