Impact
A crafted OCI index graph can cause extremely high CPU and memory consumption during image pull operations in containerd. This resource exhaustion stalls the ContainerCreating phase and can destabilize the node or runtime at larger image sizes, resulting in a denial‑of‑service condition for containers awaiting start. The vulnerability stems from uncontrolled allocation based on the supplied OCI index and leads to resource limits being exceeded before the image is fully processed.
Affected Systems
The issue exists in containerd releases prior to 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1. Any system running an affected containerd version that pulls images from a source that can supply a crafted OCI index graph is at risk. Users should verify the containerd version and upgrade if it falls below the listed fixed releases.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity, and the vulnerability is not currently listed in the CISA KEV catalog. Exploitation requires the ability to initiate an image pull with a malicious OCI index; this is typically a remote attack vector. No EPSS score is available, so the exploitation probability is uncertain, but the impact is measurable if an attacker can supply a crafted index during normal image pull activities.
OpenCVE Enrichment