PT-2026-50900 · Unknown+3 · Kubernetes Containerd+3
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
containerd versions prior to 2.3.2
containerd versions prior to 2.2.5
containerd versions prior to 2.1.9
containerd versions prior to 2.0.10
containerd versions prior to 1.7.33
Description
The CRI checkpoint import process fails to validate image references specified within a checkpoint image's configuration. An attacker with permissions to create pods can use a crafted checkpoint image to force the system to pull a malicious image and assign it an arbitrary local tag, poisoning the node's local image cache. If other pods on the same node use the poisoned tag with an
IfNotPresent or Never pull policy, they will execute the malicious image instead of the legitimate one, allowing the attacker to execute arbitrary code under the victim pod's identity. Additionally, some related issues can lead to host-root command execution during restore.Recommendations
Update to version 2.3.2.
Update to version 2.2.5.
Update to version 2.1.9.
Update to version 2.0.10.
Update to version 1.7.33.
Only allow trusted images to be pulled.
Exploit
Fix
DoS
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Red Os
Ubuntu
Kubernetes Containerd