CVE-2021-41103: Insufficiently restricted permissions on plugin directories

Published Oct 4, 2021
·
Updated

Impact A bug was found in containerd where container root directories and some plugins had insufficiently restricted permissions, allowing otherwise unprivileged Linux users to traverse directory contents and execute programs. When containers included executable programs with extended permission bits (such as setuid), unprivileged Linux users could discover and execute those programs. When the UID of an unprivileged Linux user on the host collided with the file owner or group inside a container, the unprivileged Linux user on the host could discover, read, and modify those files.

Patches This vulnerability has been fixed in containerd 1.4.11 and containerd 1.5.7. Users should update to these version when they are released and may restart containers or update directory permissions to mitigate the vulnerability.

Workarounds Limit access to the host to trusted users. Update directory permission on container bundles directories.

For more information If you have any questions or comments about this advisory: Open an issue in github.com/containerd/containerd Email us at security@containerd.io

Other sources

A flaw was found in the containerd package. Containerd could allow a local authenticated attacker to traverse directories on the system, due to improper restricted permissions on the container root and plugin directories. This issue could allow an attacker to send a specially-crafted request containing "dot dot" sequences (/../) to view directory contents and execute programs.

containerd is an open source container runtime with an emphasis on simplicity, robustness and portability. A bug was found in containerd where container root directories and some plugins had insufficiently restricted permissions, allowing otherwise unprivileged Linux users to traverse directory contents and execute programs. When containers included executable programs with extended permission bits (such as setuid), unprivileged Linux users could discover and execute those programs. When the UID of an unprivileged Linux user on the host collided with the file owner or group inside a container, the unprivileged Linux user on the host could discover, read, and modify those files. This vulnerability has been fixed in containerd 1.4.11 and containerd 1.5.7. Users should update to these version when they are released and may restart containers or update directory permissions to mitigate the vulnerability. Users unable to update should limit access to the host to trusted users. Update directory permission on container bundles directories.

Affected Software

10 affected componentsFixes available
debian/containerd
1.4.13~ds1-1~deb11u41.4.13~ds1-1~deb11u21.6.20~ds1-11.6.20~ds1-2
go/github.com/containerd/containerd>=1.5.0<1.5.7
1.5.7
go/github.com/containerd/containerd<1.4.11
1.4.11
redhat/containerd<1.4.11
1.4.11
redhat/containerd<1.5.7
1.5.7
linuxfoundation Containerd<1.4.11
linuxfoundation Containerd>=1.5.0<1.5.7
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Debian Debian Linux=11.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/containerd to a version that resolves this vulnerability.

    Fixed in 1.4.13~ds1-1~deb11u4Fixed in 1.4.13~ds1-1~deb11u2Fixed in 1.6.20~ds1-1Fixed in 1.6.20~ds1-2
  2. Upgrade

    Upgrade go/github.com/containerd/containerd to a version that resolves this vulnerability.

    Fixed in 1.5.7
  3. Upgrade

    Upgrade go/github.com/containerd/containerd to a version that resolves this vulnerability.

    Fixed in 1.4.11
  4. Upgrade

    Upgrade redhat/containerd to a version that resolves this vulnerability.

    Fixed in 1.4.11
  5. Upgrade

    Upgrade redhat/containerd to a version that resolves this vulnerability.

    Fixed in 1.5.7
  6. Upgrade

    Upgrade containerd to a version that resolves this vulnerability.

    Fixed in 1.4.11
  7. Upgrade

    Upgrade containerd to a version that resolves this vulnerability.

    Fixed in 1.5.7
  8. Configuration

    Update directory permission on container bundles directories to mitigate the vulnerability.

    containerd directory permissions on container bundle directories = updated/restricted
  9. Compensating control

    Limit access to the host to trusted users if you cannot update containerd.

Event History

Oct 4, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
12:00 AM
RemedyDescriptionSeverityWeaknessAffected Software
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·08:14 PM

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is CVE-2021-41103?

CVE-2021-41103 is a vulnerability found in the containerd package that allows a local authenticated attacker to escalate privileges.

2

What is containerd?

containerd is an open source container runtime known for its simplicity, robustness, and portability.

3

How does CVE-2021-41103 affect containerd?

CVE-2021-41103 affects containerd by allowing unprivileged Linux users to traverse directory contents and potentially escalate their privileges.

4

What is the severity of CVE-2021-41103?

The severity of CVE-2021-41103 is high with a CVSS score of 7.8.

5

How can I fix CVE-2021-41103 in containerd?

To fix CVE-2021-41103 in containerd, update to version 1.4.11 or 1.5.7, depending on the specific version you are using.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203