Description
containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine in internal/cri/server/container_execsync.go when CRI ExecSync is used by exec probes or lifecycle hooks that launch long-lived background child processes retaining standard input and output pipes. The input and output drain phase has no default timeout and did not stop when the request context was canceled, so repeated ExecSync invocations can accumulate blocked goroutines and host memory. The resulting resource exhaustion can cause the OOM killer to terminate containerd, leaving the container runtime unavailable until restart. Deployments not using containerd's CRI implementation and containers not running on Linux are not affected. This issue is fixed in versions 1.7.35, 2.0.12, 2.2.8, and 2.3.5.
Published: 2026-09-14
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Node-level Denial of Service
Action: Apply Patch
AI Analysis

Impact

Containerd’s CRI ExecSync component has a goroutine leak: when ExecSync is invoked by probes or lifecycle hooks that launch long‑lived background child processes that keep standard input and output pipes open, the drainExecSyncIO goroutine can block indefinitely. Because the drain phase has no timeout and does not honor request‑context cancellation, each successive ExecSync call leaves behind a blocked goroutine and consumes memory. Over time, this memory growth can exhaust the host, triggering the OOM killer to terminate containerd, which causes the container runtime to become unavailable until the daemon is restarted. Affected prior to containerd 1.7.35, 2.0.12, 2.2.8, and 2.3.5.

Affected Systems

Linux deployments running containerd with the CRI plugin and older than v1.7.35, v2.0.12, v2.2.8, or v2.3.5 are affected. The vulnerability does not impact containerd installations that do not use the CRI implementation and containers not running on Linux are not affected. The affected component is the containerd daemon process itself.

Risk and Exploitability

The CVSS score of 6.8 classifies the vulnerability as moderate severity. The EPSS score of < 1% indicates a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalogue. Based on the description, an attacker would need to trigger ExecSync requests, which may require local or elevated privileges; this requirement is inferred from the need to influence probes or lifecycle hooks running within the node.

Generated by OpenCVE AI on September 20, 2026 at 23:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade containerd to version 1.7.35 or later, or to v2.0.12, v2.2.8, or v2.3.5 to remove the goroutine leak
  • If upgrading is not feasible, disable the use of ExecSync in lifecycle hooks and exec probes or restructure background processes so that their stdin and stdout pipes close promptly
  • Continuously monitor containerd memory usage for abnormal growth and restart the runtime proactively when memory usage rises to mitigate OOM‑induced downtime

Generated by OpenCVE AI on September 20, 2026 at 23:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-7jxh-36q5-gcqv containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service
History

Tue, 15 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Tue, 15 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Containerd
Containerd containerd
Vendors & Products Containerd
Containerd containerd

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine in internal/cri/server/container_execsync.go when CRI ExecSync is used by exec probes or lifecycle hooks that launch long-lived background child processes retaining standard input and output pipes. The input and output drain phase has no default timeout and did not stop when the request context was canceled, so repeated ExecSync invocations can accumulate blocked goroutines and host memory. The resulting resource exhaustion can cause the OOM killer to terminate containerd, leaving the container runtime unavailable until restart. Deployments not using containerd's CRI implementation and containers not running on Linux are not affected. This issue is fixed in versions 1.7.35, 2.0.12, 2.2.8, and 2.3.5.
Title containerd CRI ExecSync Goroutine Leak Leading to Node-Level Denial of Service
Weaknesses CWE-400
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Containerd Containerd
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T17:34:38.488Z

Reserved: 2026-06-09T17:05:25.059Z

Link: CVE-2026-53495

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T18:17:51.053

Modified: 2026-09-25T14:10:13.927

Link: CVE-2026-53495

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-14T17:18:06Z

Links: CVE-2026-53495 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:15:04Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-772

    Missing Release of Resource after Effective Lifetime