Impact
A flaw in the LS‑MT index loading routine of containerd overlaybd allows an integer overflow when processing the index_bytes field from an untrusted registry blob. This overflow can lead to an out‑of‑bounds read or write on the heap, potentially corrupting memory or causing a crash. The vulnerability is triggered when multiple overlaybd‑backed containers use the same blob, giving an attacker a path to manipulate memory during startup or operation.
Affected Systems
containerd component overlaybd, versions up to 1.0.18. The vulnerability is present only for overlaybd images that are fetched from external registries and used in scenarios with more than one container sharing the same overlaybd backing.
Risk and Exploitability
The CVSS base score of 6.8 indicates a medium severity threat that could impact confidentiality, integrity, or availability if exploited. No EPSS score is available, and the issue is not listed in CISA’s KEV catalog. The attack vector is inferred to be remote via a registry that an attacker can inject malicious blobs into; however, the vulnerability requires the attacker to supply a specially crafted overlaybd blob that the host pulls from an untrusted source.
OpenCVE Enrichment