PT-2025-22285 · Unknown+1 · Kubernetes Containerd
Tõnis Tiigi
·
Published
2025-05-20
·
Updated
2025-09-19
·
CVE-2025-47290
CVSS v4.0
7.6
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U |
Name of the Vulnerable Software and Affected Versions
containerd version 2.1.0
Description
A time-of-check to time-of-use (TOCTOU) vulnerability was found in containerd. This issue allows specially crafted container images to arbitrarily modify the host file system while unpacking an image during an image pull.
Recommendations
For containerd version 2.1.0, update to version 2.1.1 to resolve the issue.
As a temporary workaround, ensure that only trusted images are used and that only trusted users have permissions to import images.
Exploit
Fix
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kubernetes Containerd