CVE-2026-46680

EUVD-2026-41103
containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 12.95%
Affected Products (NVD)
VendorProductVersion
linuxfoundationcontainerd
1.7.27 ≤
𝑥
< 1.7.32
linuxfoundationcontainerd
2.0.4 ≤
𝑥
< 2.0.9
linuxfoundationcontainerd
2.1.0 ≤
𝑥
< 2.2.4
linuxfoundationcontainerd
2.3.0 ≤
𝑥
< 2.3.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
containerd
bookworm
vulnerable
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
vulnerable
sid
vulnerable
trixie
vulnerable
trixie (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
containerd
bionic
needed
focal
needed
jammy
needed
noble
needed
questing
ignored
resolute
needed
containerd-app
focal
needed
jammy
needed
noble
needed
questing
ignored
resolute
needed
containerd-stable
jammy
dne
noble
dne
questing
ignored
resolute
needed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
runfinch-finch
Amazon Linux 2023
0:1.17.2-1.amzn2023.0.1
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
moby-containerd-cc
Azure Linux 3.0
0:1.7.7-15.azl3
fixed