Impact
Containerd’s CRI ExecSync component has a goroutine leak: when ExecSync is invoked by probes or lifecycle hooks that launch long‑lived background child processes that keep standard input and output pipes open, the drainExecSyncIO goroutine can block indefinitely. Because the drain phase has no timeout and does not honor request‑context cancellation, each successive ExecSync call leaves behind a blocked goroutine and consumes memory. Over time, this memory growth can exhaust the host, triggering the OOM killer to terminate containerd, which causes the container runtime to become unavailable until the daemon is restarted. Affected prior to containerd 1.7.35, 2.0.12, 2.2.8, and 2.3.5.
Affected Systems
Linux deployments running containerd with the CRI plugin and older than v1.7.35, v2.0.12, v2.2.8, or v2.3.5 are affected. The vulnerability does not impact containerd installations that do not use the CRI implementation and containers not running on Linux are not affected. The affected component is the containerd daemon process itself.
Risk and Exploitability
The CVSS score of 6.8 classifies the vulnerability as moderate severity. The EPSS score of < 1% indicates a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalogue. Based on the description, an attacker would need to trigger ExecSync requests, which may require local or elevated privileges; this requirement is inferred from the need to influence probes or lifecycle hooks running within the node.
OpenCVE Enrichment
Github GHSA