CVE-2026-107446: Integer Overflow
containerd overlaybd through 1.0.18 has a doloadindex (LSMT index loading) integer overflow (and resultant out-of-bounds heap access) for indexbytes, if an untrusted overlaybd blob from a registry is used in a scenario with multiple overlaybd-backed containers.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments using containerd overlaybd through version 1.0.18 are affected when they use an untrusted overlaybd blob from a registry in a scenario involving multiple overlaybd-backed containers.
What does an attacker need to exploit this vulnerability?
An attacker needs an untrusted overlaybd blob to be used from a registry. The affected scenario also requires multiple containers backed by overlaybd.
What is the likely impact of successful exploitation?
The integer overflow in LSMT index loading can result in an out-of-bounds heap access. The supplied severity vector indicates network reachability, no required privileges or user interaction, and an availability impact.