Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-m6hq-p25p-ffr2 | containerd CRI server: Host memory exhaustion through Attach goroutine leak |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 07 Nov 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 07 Nov 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Containerd
Containerd containerd Linuxfoundation Linuxfoundation containerd |
|
| Vendors & Products |
Containerd
Containerd containerd Linuxfoundation Linuxfoundation containerd |
Fri, 07 Nov 2025 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4, and 2.2.0-beta.0 through 2.2.0-rc.1 contain a bug in the CRI Attach implementation where a user can exhaust memory on the host due to goroutine leaks. This issue is fixed in versions 1.7.29, 2.0.7, 2.1.5 and 2.2.0. To workaround this vulnerability, users can set up an admission controller to control accesses to pods/attach resources. | |
| Title | containerd CRI server: Host memory exhaustion through Attach goroutine leak | |
| Weaknesses | CWE-401 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-07T17:42:07.929Z
Reserved: 2025-10-30T17:40:52.028Z
Link: CVE-2025-64329
Updated: 2025-11-07T17:42:02.511Z
Status : Awaiting Analysis
Published: 2025-11-07T05:16:08.017
Modified: 2025-11-12T16:20:22.257
Link: CVE-2025-64329
No data.
OpenCVE Enrichment
Updated: 2025-11-07T10:53:38Z
Github GHSA