Description
containerd overlaybd through 1.0.18 has a do_load_index (LSMT index loading) integer overflow (and resultant out-of-bounds heap access) for index_bytes, if an untrusted overlaybd blob from a registry is used in a scenario with multiple overlaybd-backed containers.
Published: 2026-10-08
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: Out-of-Bounds Heap Access via integer overflow
Action: Upgrade overlaybd
AI Analysis

Impact

A flaw in the LS‑MT index loading routine of containerd overlaybd allows an integer overflow when processing the index_bytes field from an untrusted registry blob. This overflow can lead to an out‑of‑bounds read or write on the heap, potentially corrupting memory or causing a crash. The vulnerability is triggered when multiple overlaybd‑backed containers use the same blob, giving an attacker a path to manipulate memory during startup or operation.

Affected Systems

containerd component overlaybd, versions up to 1.0.18. The vulnerability is present only for overlaybd images that are fetched from external registries and used in scenarios with more than one container sharing the same overlaybd backing.

Risk and Exploitability

The CVSS base score of 6.8 indicates a medium severity threat that could impact confidentiality, integrity, or availability if exploited. No EPSS score is available, and the issue is not listed in CISA’s KEV catalog. The attack vector is inferred to be remote via a registry that an attacker can inject malicious blobs into; however, the vulnerability requires the attacker to supply a specially crafted overlaybd blob that the host pulls from an untrusted source.

Generated by OpenCVE AI on October 8, 2026 at 05:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to containerd overlaybd version 1.0.19 or later, which resolves the integer overflow in LS‑MT index loading.
  • Limit registry access to trusted and signed sources; avoid pulling overlaybd blobs from public or untrusted registries.
  • Implement runtime integrity checks for overlaybd blobs, verifying checksums or signatures before mounting.

Generated by OpenCVE AI on October 8, 2026 at 05:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in LS‑MT Index Loading of containerd overlaybd

Thu, 08 Oct 2026 04:00:00 +0000

Type Values Removed Values Added
Description containerd overlaybd through 1.0.18 has a do_load_index (LSMT index loading) integer overflow (and resultant out-of-bounds heap access) for index_bytes, if an untrusted overlaybd blob from a registry is used in a scenario with multiple overlaybd-backed containers.
Weaknesses CWE-190
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-08T03:37:19.484Z

Reserved: 2026-10-08T03:37:18.693Z

Link: CVE-2026-107446

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T04:17:19.410

Modified: 2026-10-08T04:17:19.410

Link: CVE-2026-107446

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T06:00:10Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound