<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T17:45:16.284342+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-53495</id>
    <title>BELL-CVE-2026-53495</title>
    <updated>2026-10-03T17:45:16.290770+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: containerd, Alpaquita:25: containerd, Alpaquita:stream: containerd</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-53495"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-mu77923</id>
    <title>CLEANSTART-2026-MU77923 — Security fix for CVE-2026-53495 applied in: rancher-fleet-agent 0.15.6-r1</title>
    <updated>2026-10-03T17:45:16.290819+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: rancher-fleet-agent</p>
<p>Security vulnerability affects the rancher-fleet-agent package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-mu77923"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-368048</id>
    <title>EUVD-2026-368048</title>
    <updated>2026-10-03T17:45:16.290844+00:00</updated>
    <content>EUVD-2026-368048</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-368048"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53495</id>
    <title>fkie_cve-2026-53495</title>
    <updated>2026-10-03T17:45:16.290857+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine in internal/cri/server/container_execsync.go when CRI ExecSync is used by exec probes or lifecycle hooks that launch long-lived background child processes retaining standard input and output pipes. The input and output drain phase has no default timeout and did not stop when the request context was canceled, so repeated ExecSync invocations can accumulate blocked goroutines and host memory. The resulting resource exhaustion can cause the OOM killer to terminate containerd, leaving the container runtime unavailable until restart. Deployments not using containerd's CRI implementation and containers not running on Linux are not affected. This issue is fixed in versions 1.7.35, 2.0.12, 2.2.8, and 2.3.5.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-53495"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7jxh-36q5-gcqv</id>
    <title>GHSA-7jxh-36q5-gcqv — containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service</title>
    <updated>2026-10-03T17:45:16.290884+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/containerd/containerd/v2, Go: github.com/containerd/containerd</p>
<p>### Impact</p>
<p>A bug in containerd's CRI ExecSync implementation allows exec probes and lifecycle hooks with background child processes to keep containerd's stdio-drain goroutines indefinitely blocked. Because the I/O drain phase lacks a default timeout or context cancellation handling, repeated ExecSync invocations (like probes) that include long-lived background processes against a container can cause containerd to leak goroutines and host memory. Over time, this resource exhaustion can cause the containerd daemon to be terminated by the OOM killer, rendering containerd unavailable until it is restarted. This issue affects containerd on Linux systems running with the CRI plugin enabled. Users not using containerd's CRI implementation or not running containers on Linux are not affected.</p>
<p>### Patches</p>
<p>This bug has been fixed in containerd 2.3.5, 2.2.8, 2.0.12, and 1.7.35. Users should update to these versions to resolve the issue.</p>
<p>### Workarounds</p>
<p>Ensure exec probes and lifecycle hooks do not launch long-lived background child processes.</p>
<p>### Credits</p>
<p>The containerd project would like to thank XlabAI Team of Tencent Xuanwu Lab (xlabai@tencent.com), including Guannan Wang, Zhanpeng Liu, Jiashuo Liang, and Guancheng Li, and @IamwhatIamSY who independently discovered and responsibly disclosed this issue in accordance with the [containerd security policy](https://github.com/containerd/project/blob/main/SECURITY.md).</p>
<p>### For more information</p>
<p>If there are any questions or comments…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7jxh-36q5-gcqv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-53495</id>
    <title>msrc_CVE-2026-53495 — containerd CRI ExecSync Goroutine Leak Leading to Node-Level Denial of Service</title>
    <updated>2026-10-03T17:45:16.290934+00:00</updated>
    <content>msrc_CVE-2026-53495</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-53495"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11766-1</id>
    <title>openSUSE-SU-2026:11766-1 — hauler-2.1.0-4.1 on GA media</title>
    <updated>2026-10-03T17:45:16.290952+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>hauler-2.1.0-4.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11766-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-53495</id>
    <title>UBUNTU-CVE-2026-53495</title>
    <updated>2026-10-03T17:45:16.290966+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: containerd, Ubuntu:Pro:18.04:LTS: containerd, Ubuntu:Pro:20.04:LTS: containerd, Ubuntu:Pro:20.04:LTS: containerd-app, Ubuntu:22.04:LTS: containerd, Ubuntu:Pro:22.04:LTS: containerd-app, Ubuntu:24.04:LTS: containerd-app, Ubuntu:Pro:24.04:LTS: containerd, Ubuntu:26.04:LTS: containerd-app, Ubuntu:26.04:LTS: containerd-stable and 1 more</p>
<p>containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine in internal/cri/server/container_execsync.go when CRI ExecSync is used by exec probes or lifecycle hooks that launch long-lived background child processes retaining standard input and output pipes. The input and output drain phase has no default timeout and did not stop when the request context was canceled, so repeated ExecSync invocations can accumulate blocked goroutines and host memory. The resulting resource exhaustion can cause the OOM killer to terminate containerd, leaving the container runtime unavailable until restart. Deployments not using containerd's CRI implementation and containers not running on Linux are not affected. This issue is fixed in versions 1.7.35, 2.0.12, 2.2.8, and 2.3.5.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-53495"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3494</id>
    <title>WID-SEC-W-2026-3494 — Docker Desktop: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-03T17:45:16.291003+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in Docker Desktop ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3494"/>
  </entry>
</feed>
