<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – containerd (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/containerd.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/containerd-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – containerd (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:59 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-24054 – Kata Containers is an open source project focusing on a standard implementation ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24054</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24054</guid>
    <pubDate>Thu, 29 Jan 2026 18:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-24054</strong></p>
  <p>Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 3.26.0, when a container image is malformed or contains no layers, containerd falls back to bind-mounting an empty snapshotter directory for the container rootfs. When the Kata runtime attempts to mount the container rootfs, the b…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24054">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-25621 – containerd is an open-source container runtime. Versions 0.1.0 through 1.7.28, 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25621</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25621</guid>
    <pubDate>Thu, 06 Nov 2025 19:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-25621</strong></p>
  <p>containerd is an open-source container runtime. Versions 0.1.0 through 1.7.28, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4 and 2.2.0-beta.0 through 2.2.0-rc.1 have an overly broad default permission vulnerability. Directory paths `/var/lib/containerd`, `/run/containerd/io.containerd.grpc.v1.cri` and `/run/containerd/io.containerd.sandbox.controller.v1.shim` were all created with incorr…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-279</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25621">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-47291 – containerd is an open-source container runtime. A bug was found in the container...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47291</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47291</guid>
    <pubDate>Wed, 21 May 2025 18:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-47291</strong></p>
  <p>containerd is an open-source container runtime. A bug was found in the containerd's CRI implementation where containerd, starting in version 2.0.1 and prior to version 2.0.5, doesn't put usernamespaced containers under the Kubernetes' cgroup hierarchy, therefore some Kubernetes limits are not honored. This may cause a denial of service of the Kubernetes node. This bug has been fixed in containerd…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47291">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24778 – The imgcrypt library provides API exensions for containerd to support encrypted ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24778</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24778</guid>
    <pubDate>Fri, 25 Mar 2022 18:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24778</strong></p>
  <p>The imgcrypt library provides API exensions for containerd to support encrypted container images and implements the ctd-decoder command line tool for use by containerd to decrypt encrypted container images. The imgcrypt function `CheckAuthorization` is supposed to check whether the current used is authorized to access an encrypted image and prevent the user from running an image that another user…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24778">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-23648 – containerd is a container runtime available as a daemon for Linux and Windows. A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23648</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23648</guid>
    <pubDate>Thu, 03 Mar 2022 14:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-23648</strong></p>
  <p>containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.14.12 where containers launched through containerd’s CRI implementation on Linux with a specially-crafted image configuration could gain access to read-only copies of arbitrary files and directories on the host. This may bypass any policy-based enforc…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23648">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-43816 – containerd is an open source container runtime. On installations using SELinux, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-43816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-43816</guid>
    <pubDate>Wed, 05 Jan 2022 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-43816</strong></p>
  <p>containerd is an open source container runtime. On installations using SELinux, such as EL8 (CentOS, RHEL), Fedora, or SUSE MicroOS, with containerd since v1.5.0-beta.0 as the backing container runtime interface (CRI), an unprivileged pod scheduled to the node may bind mount, via hostPath volume, any privileged, regular file on disk for complete read/write access (sans delete). Such is achieved b…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-281</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43816">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-41103 – containerd is an open source container runtime with an emphasis on simplicity, r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41103</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41103</guid>
    <pubDate>Mon, 04 Oct 2021 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-41103</strong></p>
  <p>containerd is an open source container runtime with an emphasis on simplicity, robustness and portability. A bug was found in containerd where container root directories and some plugins had insufficiently restricted permissions, allowing otherwise unprivileged Linux users to traverse directory contents and execute programs. When containers included executable programs with extended permission bi…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41103">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
