REDHAT-BUG-2495815: High severity containerd containerd vulnerability
containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
containerd CRI pluginto a version that resolves this vulnerability.Fixed in 1.7.33 - Upgrade
Upgrade
containerd CRI pluginto a version that resolves this vulnerability.Fixed in 2.3.2 - Upgrade
Upgrade
containerd CRI pluginto a version that resolves this vulnerability.Fixed in 2.2.5 - Upgrade
Upgrade
containerd CRI pluginto a version that resolves this vulnerability.Fixed in 2.1.9 - Upgrade
Upgrade
containerd CRI pluginto a version that resolves this vulnerability.Fixed in 2.0.10
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2495815?
The severity of REDHAT-BUG-2495815 is classified as high with a score of 7.
How do I fix REDHAT-BUG-2495815?
To fix REDHAT-BUG-2495815, upgrade containerd to versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, or 2.0.10 or later.
What are the risks associated with REDHAT-BUG-2495815?
The risks associated with REDHAT-BUG-2495815 include the potential for arbitrary command execution on the host system.
Which containerd versions are affected by REDHAT-BUG-2495815?
REDHAT-BUG-2495815 affects containerd versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.
What is containerd in relation to REDHAT-BUG-2495815?
Containerd is an open-source container runtime that is affected by the vulnerability described in REDHAT-BUG-2495815.