Description
containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file where a limit was not applied could cause a denial of service. This bug has been fixed in containerd 1.6.18 and 1.5.18. Users should update to these versions to resolve the issue. As a workaround, ensure that only trusted images are used and that only trusted users have permissions to import images.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0597 | containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file where a limit was not applied could cause a denial of service. This bug has been fixed in containerd 1.6.18 and 1.5.18. Users should update to these versions to resolve the issue. As a workaround, ensure that only trusted images are used and that only trusted users have permissions to import images. |
Github GHSA |
GHSA-259w-8hf6-59c2 | OCI image importer memory exhaustion in github.com/containerd/containerd |
Ubuntu USN |
USN-6202-1 | containerd vulnerabilities |
References
History
Mon, 10 Mar 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-03-10T21:10:44.159Z
Reserved: 2023-02-03T16:59:18.242Z
Link: CVE-2023-25153
Updated: 2024-08-02T11:18:35.221Z
Status : Modified
Published: 2023-02-16T15:15:19.477
Modified: 2024-11-21T07:49:12.643
Link: CVE-2023-25153
OpenCVE Enrichment
No data.
EUVD
Github GHSA
Ubuntu USN