PT-2026-51048 · Unknown+3 · Kubernetes Containerd+3

·

CVE-2026-47262

·

Published

2026-06-19

·

Updated

2026-08-20

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions containerd versions prior to 2.3.2 containerd versions prior to 2.2.5 containerd versions prior to 2.1.9 containerd versions prior to 2.0.10 containerd versions prior to 1.7.33
Description A maliciously crafted image can cause a Denial of Service (DoS) condition. When a container is created from such an image, memory exhaustion occurs, resulting in an Out Of Memory (OOM) kill of the containerd process. This action makes the container runtime API unavailable and can disrupt clients, including the Docker Engine or Kubernetes control-plane components.
Recommendations Update to version 2.3.2. Update to version 2.2.5. Update to version 2.1.9. Update to version 2.0.10. Update to version 1.7.33. Ensure that only trusted images are used and that only trusted users have permissions to import images or schedule pods.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-90176
AZL-91782
CLEANSTART-2026-AQ98798
CVE-2026-47262
GHSA-JPCC-P29G-P8MQ
GO-2026-5475
OESA-2026-2892
OESA-2026-2893
OESA-2026-2894
OESA-2026-2895
OESA-2026-3007
OPENSUSE-SU-2026:11102-1
OPENSUSE-SU-2026:11107-1
OPENSUSE-SU-2026:21072-1
OPENSUSE-SU-2026:21213-1
OPENSUSE-SU-2026:21483-1
RHSA-2026:25535
RHSA-2026:26990
RHSA-2026:32963
RHSA-2026:32974
RHSA-2026:35111
USN-8471-1
USN-8472-1
USN-8473-1

Affected Products

Linuxmint
Red Os
Ubuntu
Kubernetes Containerd