PT-2026-51057 · Unknown+4 · Kubernetes Containerd+3
CVSS v4.0
8.2
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
containerd versions prior to 2.1.9
containerd versions prior to 2.2.5
containerd versions prior to 2.3.2
Description
A bug in the CRI plugin allows the restoration of
container.log from a checkpoint image without validating a symlinked path. This can lead to an arbitrary file read on the host system when using kubectl logs.Recommendations
Update to version 2.1.9.
Update to version 2.2.5.
Update to version 2.3.2.
Ensure that only trusted images and checkpoints are used.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kubernetes Containerd
Linuxmint
Red Os
Ubuntu