CVE-2026-53488
EUVD-2026-4086001.07.2026, 02:17
containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| linuxfoundation | containerd | 1.7.0 ≤ 𝑥 < 1.7.33 |
| linuxfoundation | containerd | 2.0.0 ≤ 𝑥 < 2.0.10 |
| linuxfoundation | containerd | 2.1.0 ≤ 𝑥 < 2.1.9 |
| linuxfoundation | containerd | 2.2.0 ≤ 𝑥 < 2.2.5 |
| linuxfoundation | containerd | 2.3.0 ≤ 𝑥 < 2.3.2 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| containerd |
| ||||||||||||
| containerd-app |
| ||||||||||||
| containerd-stable |
|
Amazon Linux Releases
Amazon Package | |||
|---|---|---|---|
| containerd |
| ||
| containerd-debuginfo |
| ||
| containerd-debugsource |
| ||
| containerd-stress |
| ||
| containerd-stress-debuginfo |
|
Azure Linux Releases
Common Weakness Enumeration
Vulnerability Media Exposure