Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
containerd Security Update: Malicious Images Cause System Disruption
OESA-2026-2895
Summary
containerd, a key component of container-based systems like Docker and Kubernetes, has released a security update to fix a vulnerability that can cause a Denial of Service (DoS) condition when a malicious image is used. This can disrupt systems relying on containerd, such as Docker and Kubernetes. To protect your system, update to the latest version of containerd.
What to do
- Update containerd to version 1.6.22-29.oe2403sp1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| openEuler:24.03-LTS-SP1 | – | containerd |
< 1.6.22-29.oe2403sp1 Fix: upgrade to 1.6.22-29.oe2403sp1
|
Original title
containerd security update
Original description
containerd is an industry-standard container runtime with an emphasis on simplicity, robustness and portability. It is available as a daemon for Linux and Windows, which can manage the complete container lifecycle of its host system: image transfer and storage, container execution and supervision, low-level storage and network attachments, etc.
Security Fix(es):
containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vulnerability that allows a maliciously crafted image to cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occurs, leading to an Out Of Memory (OOM) kill of the containerd process. This renders the container runtime API unavailable and can disrupt clients such as the Docker Engine or Kubernetes control-plane components. This issue has been fixed in versions 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2.(CVE-2026-47262)
containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.(CVE-2026-53488)
Security Fix(es):
containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vulnerability that allows a maliciously crafted image to cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occurs, leading to an Out Of Memory (OOM) kill of the containerd process. This renders the container runtime API unavailable and can disrupt clients such as the Docker Engine or Kubernetes control-plane components. This issue has been fixed in versions 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2.(CVE-2026-47262)
containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.(CVE-2026-53488)
- https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-47262 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-53488 Vendor Advisory
Published: 9 Jul 2026 · Updated: 9 Jul 2026 · First seen: 9 Jul 2026