Security vulnerabilities and automated fixes for containerd issues
2 posts found
A critical vulnerability in containerd v1.7.32 allowed attackers to execute arbitrary commands as root on the host by manipulating image configuration labels processed by the CRI plugin. Upgrading to containerd v1.7.33 eliminates this attack vector through improved input validation.
A high-severity privilege escalation vulnerability (CVE-2026-46680) was discovered in containerd v1.7.31, where incorrect user ID handling could allow an attacker to escalate privileges within container environments. The fix upgrades the `github.com/containerd/containerd` dependency from v1.7.31 to v1.7.32, which corrects the UID handling logic and introduces additional transitive dependencies for secure path resolution.