Loading vulnerability details...
A bug was found in containerd where the CRI plugin restores container.log from a checkpoint image without validating a symlinked path. This could result in reading an arbitrary file on the host via kubectl logs.
This bug has been fixed in the following containerd versions:
Users should update to these versions to resolve the issue.
Ensure that only trusted images and checkpoints are used.
The containerd project would like to thank @gouldnicholas and @davidrxchester, Yuming Zhang and Song Li of Zhejiang University, Sangwon Ryu (@sangwon090), Henry Beberman (@hbeberman) of Microsoft, the GKE Security Team using Gemini, Anthropic Research, in collaboration with Claude, Robert Prast (@robertprast), Kyle Elliott (@kyle-elliott-tob) of Trail of Bits, and Zhenchen Wang (@Plucky923), who independently discovered and responsibly disclosed this issue in accordance with the containerd security policy.
If you have any questions or comments about this advisory:
To report a security issue in containerd:
A bug was found in containerd where the CRI plugin restores container.log from a checkpoint image without validating a symlinked path. This could result in reading an arbitrary file on the host via kubectl logs.
This bug has been fixed in the following containerd versions:
Users should update to these versions to resolve the issue.
Ensure that only trusted images and checkpoints are used.
The containerd project would like to thank @gouldnicholas and @davidrxchester, Yuming Zhang and Song Li of Zhejiang University, Sangwon Ryu (@sangwon090), Henry Beberman (@hbeberman) of Microsoft, the GKE Security Team using Gemini, Anthropic Research, in collaboration with Claude, Robert Prast (@robertprast), Kyle Elliott (@kyle-elliott-tob) of Trail of Bits, and Zhenchen Wang (@Plucky923), who independently discovered and responsibly disclosed this issue in accordance with the containerd security policy.
If you have any questions or comments about this advisory:
To report a security issue in containerd:
This medium-severity vulnerability could be exploited under certain conditions to compromise security controls or access sensitive information. Should be addressed in a timely manner.
Probability of exploitation in the next 30 days · more likely than 6.3% of all CVEs.
Apply security patches to version 2.1.9 immediately
Isolate affected systems from untrusted networks until patching is complete
Implement enhanced monitoring for exploitation attempts and unusual behavior