<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T08:42:47.656927+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-05412</id>
    <title>bdu:2022-05412</title>
    <updated>2026-10-03T08:42:47.828820+00:00</updated>
    <content>bdu:2022-05412</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-05412"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2022-31030</id>
    <title>Withdrawn: BELL-CVE-2022-31030 — CVE-2022-31030 does not affect BellSoft software</title>
    <updated>2026-10-03T08:42:47.828860+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2022-31030"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0199</id>
    <title>certfr-2024-avi-0199 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
    <updated>2026-10-03T08:42:47.828907+00:00</updated>
    <content>certfr-2024-avi-0199</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0199"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2025-ug08794</id>
    <title>CLEANSTART-2025-UG08794 — containerd is an open source container runtime</title>
    <updated>2026-10-03T08:42:47.828937+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: containerd</p>
<p>Security vulnerability affects the containerd package. containerd is an open source container runtime.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2025-ug08794"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-16785</id>
    <title>EUVD-2026-16785</title>
    <updated>2026-10-03T08:42:47.828965+00:00</updated>
    <content>EUVD-2026-16785</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-16785"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-31030</id>
    <title>fkie_cve-2022-31030</title>
    <updated>2026-10-03T08:42:47.828976+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>containerd is an open source container runtime. A bug was found in the containerd's CRI implementation where programs inside a container can cause the containerd daemon to consume memory without bound during invocation of the `ExecSync` API. This can cause containerd to consume all available memory on the computer, denying service to other legitimate workloads. Kubernetes and crictl can both be configured to use containerd's CRI implementation; `ExecSync` may be used when running probes or when executing processes via an "exec" facility. This bug has been fixed in containerd 1.6.6 and 1.5.13. Users should update to these versions to resolve the issue. Users unable to upgrade should ensure that only trusted images and commands are used.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-31030"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5ffw-gxpp-mxpf</id>
    <title>GHSA-5ffw-gxpp-mxpf — containerd CRI plugin: Host memory exhaustion through ExecSync</title>
    <updated>2026-10-03T08:42:47.829002+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/containerd/containerd</p>
<p>### Impact</p>
<p>A bug was found in containerd's CRI implementation where programs inside a container can cause the containerd daemon to consume memory without bound during invocation of the `ExecSync` API.  This can cause containerd to consume all available memory on the computer, denying service to other legitimate workloads.  Kubernetes and crictl can both be configured to use containerd's CRI implementation; `ExecSync` may be used when running probes or when executing processes via an "exec" facility.</p>
<p>### Patches</p>
<p>This bug has been fixed in containerd 1.6.6 and 1.5.13.  Users should update to these versions to resolve the issue.</p>
<p>### Workarounds</p>
<p>Ensure that only trusted images and commands are used.</p>
<p>### References</p>
<p>* Similar fix in cri-o's CRI implementation https://github.com/cri-o/cri-o/security/advisories/GHSA-fcm2-6c3h-pg6j</p>
<p>### Credits</p>
<p>The containerd project would like to thank David Korczynski and Adam Korczynski of ADA Logics for responsibly disclosing this issue in accordance with the [containerd security policy](https://github.com/containerd/project/blob/main/SECURITY.md) during a security audit sponsored by CNCF and facilitated by OSTIF.</p>
<p>### For more information</p>
<p>If you have any questions or comments about this advisory:</p>
<p>* Open an issue in [containerd](https://github.com/containerd/containerd/issues/new/choose)
* Email us at [security@containerd.io](mailto:security@containerd.io)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5ffw-gxpp-mxpf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-31030</id>
    <title>gsd-2022-31030</title>
    <updated>2026-10-03T08:42:47.829040+00:00</updated>
    <content>gsd-2022-31030</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-31030"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-31030</id>
    <title>msrc_CVE-2022-31030 — containerd CRI plugin: Host memory exhaustion through ExecSync</title>
    <updated>2026-10-03T08:42:47.829051+00:00</updated>
    <content>msrc_CVE-2022-31030</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-31030"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1743</id>
    <title>OESA-2022-1743 — containerd security update</title>
    <updated>2026-10-03T08:42:47.829066+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: containerd, openEuler:20.03-LTS-SP3: containerd, openEuler:22.03-LTS: containerd</p>
<p>containerd is an industry-standard container runtime with an emphasis on simplicity, robustness and portability.  It is available as a daemon for Linux and Windows, which can manage the complete container lifecycle of its host system: image transfer and storage, container execution and supervision, low-level storage and network attachments, etc.

Security Fix(es):

containerd is an open source container runtime. A bug was found in the containerd&amp;apos;s CRI implementation where programs inside a container can cause the containerd daemon to consume memory without bound during invocation of the `ExecSync` API. This can cause containerd to consume all available memory on the computer, denying service to other legitimate workloads. Kubernetes and crictl can both be configured to use containerd&amp;apos;s CRI implementation; `ExecSync` may be used when running probes or when executing processes via an &amp;quot;exec&amp;quot; facility. This bug has been fixed in containerd 1.6.6 and 1.5.13. Users should update to these versions to resolve the issue. Users unable to upgrade should ensure that only trusted images and commands are used.(CVE-2022-31030)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1743"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12130-1</id>
    <title>openSUSE-SU-2024:12130-1 — containerd-1.6.6-1.1 on GA media</title>
    <updated>2026-10-03T08:42:47.829095+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>containerd-1.6.6-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12130-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:2165-1</id>
    <title>SUSE-SU-2022:2165-1 — Security update for containerd</title>
    <updated>2026-10-03T08:42:47.829111+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for containerd</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:2165-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-31030</id>
    <title>UBUNTU-CVE-2022-31030</title>
    <updated>2026-10-03T08:42:47.829125+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: containerd, Ubuntu:18.04:LTS: containerd, Ubuntu:20.04:LTS: containerd, Ubuntu:22.04:LTS: containerd</p>
<p>containerd is an open source container runtime. A bug was found in the containerd's CRI implementation where programs inside a container can cause the containerd daemon to consume memory without bound during invocation of the `ExecSync` API. This can cause containerd to consume all available memory on the computer, denying service to other legitimate workloads. Kubernetes and crictl can both be configured to use containerd's CRI implementation; `ExecSync` may be used when running probes or when executing processes via an "exec" facility. This bug has been fixed in containerd 1.6.6 and 1.5.13. Users should update to these versions to resolve the issue. Users unable to upgrade should ensure that only trusted images and commands are used.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-31030"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3146</id>
    <title>WID-SEC-W-2023-3146 — IBM MQ Operator and Queue manager: Mehrere Schwachstellen</title>
    <updated>2026-10-03T08:42:47.829150+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM MQ Operator and Queue manager ausnutzen, um einen Denial of Service Angriff durchzuführen, Informationen offenzulegen oder Sicherheitsmaßnahmen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3146"/>
  </entry>
</feed>
