<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:12:02 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-16113</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-16113</link>
      <description>bdu:2025-16113</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-16113</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-64329</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-64329</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: containerd, Alpaquita:25: containerd, Alpaquita:stream: containerd&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: containerd, Alpaquita:25: containerd, Alpaquita:stream: containerd&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-64329</guid>
    </item>
    <item>
      <title>certfr-2025-avi-1036 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1036</link>
      <description>certfr-2025-avi-1036</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-1036</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-CD03295 — Security fixes in rancher-agent 2.11.15-r1</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-cd03295</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: rancher-agent&lt;/p&gt;
&lt;p&gt;Package rancher-agent version 2.11.15-r1 fixes 28 vulnerabilities: CVE-2026-53492, CVE-2026-50195, CVE-2026-53489, CVE-2024-40635, CVE-2024-25621...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: rancher-agent&lt;/p&gt;
&lt;p&gt;Package rancher-agent version 2.11.15-r1 fixes 28 vulnerabilities: CVE-2026-53492, CVE-2026-50195, CVE-2026-53489, CVE-2024-40635, CVE-2024-25621...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-cd03295</guid>
    </item>
    <item>
      <title>EUVD-2026-260378</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-260378</link>
      <description>EUVD-2026-260378</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-260378</guid>
    </item>
    <item>
      <title>fkie_cve-2025-64329</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-64329</link>
      <description>&lt;p&gt;containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4, and 2.2.0-beta.0 through 2.2.0-rc.1 contain a bug in the CRI Attach implementation where a user can exhaust memory on the host due to goroutine leaks. This issue is fixed in versions 1.7.29, 2.0.7, 2.1.5 and 2.2.0. To workaround this vulnerability, users can set up an admission controller to control accesses to pods/attach resources.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4, and 2.2.0-beta.0 through 2.2.0-rc.1 contain a bug in the CRI Attach implementation where a user can exhaust memory on the host due to goroutine leaks. This issue is fixed in versions 1.7.29, 2.0.7, 2.1.5 and 2.2.0. To workaround this vulnerability, users can set up an admission controller to control accesses to pods/attach resources.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-64329</guid>
    </item>
    <item>
      <title>GHSA-m6hq-p25p-ffr2 — containerd CRI server: Host memory exhaustion through Attach goroutine leak</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m6hq-p25p-ffr2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/containerd/containerd, Go: github.com/containerd/containerd/v2&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;A bug was found in containerd&amp;#39;s CRI Attach implementation where a user can exhaust memory on the host due to goroutine leaks.&lt;/p&gt;
&lt;p&gt;Repetitive calls of CRI Attach (e.g., [`kubectl attach`](https://kubernetes.io/docs/reference/kubectl/generated/kubectl_attach/)) could increase the memory usage of containerd.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This bug has been fixed in the following containerd versions:&lt;/p&gt;
&lt;p&gt;* 2.2.0
* 2.1.5
* 2.0.7
* 1.7.29&lt;/p&gt;
&lt;p&gt;Users should update to these versions to resolve the issue.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Set up an admission controller to control accesses to `pods/attach` resources.
e.g., [Validating Admission Policy](https://kubernetes.io/docs/reference/access-authn-authz/validating-admission-policy/).&lt;/p&gt;
&lt;p&gt;### Credits&lt;/p&gt;
&lt;p&gt;The containerd project would like to thank @Wheat2018 for responsibly disclosing this issue in accordance with the [containerd security policy](https://github.com/containerd/project/blob/main/SECURITY.md).&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-64329&lt;/p&gt;
&lt;p&gt;### For more information&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory:&lt;/p&gt;
&lt;p&gt;* Open an issue in [containerd](https://github.com/containerd/containerd/issues/new/choose)
* Email us at [security@containerd.io](mailto:security@containerd.io)&lt;/p&gt;
&lt;p&gt;To report a security issue in containerd:&lt;/p&gt;
&lt;p&gt;* [Report a new vulnerability](https://github.com/containerd/containerd/security/advisories/new)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/containerd/containerd, Go: github.com/containerd/containerd/v2&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;A bug was found in containerd&amp;#39;s CRI Attach implementation where a user can exhaust memory on the host due to goroutine leaks.&lt;/p&gt;
&lt;p&gt;Repetitive calls of CRI Attach (e.g., [`kubectl attach`](https://kubernetes.io/docs/reference/kubectl/generated/kubectl_attach/)) could increase the memory usage of containerd.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This bug has been fixed in the following containerd versions:&lt;/p&gt;
&lt;p&gt;* 2.2.0
* 2.1.5
* 2.0.7
* 1.7.29&lt;/p&gt;
&lt;p&gt;Users should update to these versions to resolve the issue.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Set up an admission controller to control accesses to `pods/attach` resources.
e.g., [Validating Admission Policy](https://kubernetes.io/docs/reference/access-authn-authz/validating-admission-policy/).&lt;/p&gt;
&lt;p&gt;### Credits&lt;/p&gt;
&lt;p&gt;The containerd project would like to thank @Wheat2018 for responsibly disclosing this issue in accordance with the [containerd security policy](https://github.com/containerd/project/blob/main/SECURITY.md).&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-64329&lt;/p&gt;
&lt;p&gt;### For more information&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory:&lt;/p&gt;
&lt;p&gt;* Open an issue in [containerd](https://github.com/containerd/containerd/issues/new/choose)
* Email us at [security@containerd.io](mailto:security@containerd.io)&lt;/p&gt;
&lt;p&gt;To report a security issue in containerd:&lt;/p&gt;
&lt;p&gt;* [Report a new vulnerability](https://github.com/containerd/containerd/security/advisories/new)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m6hq-p25p-ffr2</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-64329 — containerd CRI server: Host memory exhaustion through Attach goroutine leak</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-64329</link>
      <description>msrc_CVE-2025-64329</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-64329</guid>
    </item>
    <item>
      <title>OESA-2025-2752 — containerd security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2752</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: containerd&lt;/p&gt;
&lt;p&gt;containerd is an industry-standard container runtime with an emphasis on simplicity, robustness and portability.  It is available as a daemon for Linux and Windows, which can manage the complete container lifecycle of its host system: image transfer and storage, container execution and supervision, low-level storage and network attachments, etc.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;An overly broad default permission vulnerability was found in containerd.&lt;/p&gt;
&lt;p&gt;- `/var/lib/containerd` was created with the permission bits 0o711, while it should be created with 0o700
  - Allowed local users on the host to potentially access the metadata store and the content store
- `/run/containerd/io.containerd.grpc.v1.cri` was created with 0o755, while it should be created with 0o700
  - Allowed local users on the host to potentially access the contents of Kubernetes local volumes. The contents of volumes might include setuid binaries, which could allow a local user on the host to elevate privileges on the host.
- `/run/containerd/io.containerd.sandbox.controller.v1.shim` was created with 0o711, while it should be created with 0o700&lt;/p&gt;
&lt;p&gt;The directory paths may differ depending on the daemon configuration.
When the `temp` directory path is specified in the daemon configuration, that directory was also created with 0o711, while it should be created with 0o700.(CVE-2024-25621)&lt;/p&gt;
&lt;p&gt;A bug was found in containerd&amp;amp;apos;s CRI Attach implementation where a user can exhaust memory on the host due to goroutine leaks. Repetitive…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: containerd&lt;/p&gt;
&lt;p&gt;containerd is an industry-standard container runtime with an emphasis on simplicity, robustness and portability.  It is available as a daemon for Linux and Windows, which can manage the complete container lifecycle of its host system: image transfer and storage, container execution and supervision, low-level storage and network attachments, etc.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;An overly broad default permission vulnerability was found in containerd.&lt;/p&gt;
&lt;p&gt;- `/var/lib/containerd` was created with the permission bits 0o711, while it should be created with 0o700
  - Allowed local users on the host to potentially access the metadata store and the content store
- `/run/containerd/io.containerd.grpc.v1.cri` was created with 0o755, while it should be created with 0o700
  - Allowed local users on the host to potentially access the contents of Kubernetes local volumes. The contents of volumes might include setuid binaries, which could allow a local user on the host to elevate privileges on the host.
- `/run/containerd/io.containerd.sandbox.controller.v1.shim` was created with 0o711, while it should be created with 0o700&lt;/p&gt;
&lt;p&gt;The directory paths may differ depending on the daemon configuration.
When the `temp` directory path is specified in the daemon configuration, that directory was also created with 0o711, while it should be created with 0o700.(CVE-2024-25621)&lt;/p&gt;
&lt;p&gt;A bug was found in containerd&amp;amp;apos;s CRI Attach implementation where a user can exhaust memory on the host due to goroutine leaks. Repetitive…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2752</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15726-1 — containerd-1.7.29-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15726-1</link>
      <description>&lt;p&gt;containerd-1.7.29-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;containerd-1.7.29-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15726-1</guid>
    </item>
    <item>
      <title>RHSA-2026:2900 — Red Hat Security Advisory: Network Observability 1.11.0 for OpenShift</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:2900</link>
      <description>&lt;p&gt;github.com/containerd/containerd: containerd local privilege escalation node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications lodash: prototype pollution in _.unset and _.omit functions qs: qs: Denial of Service via improper input validation in array parsing runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects golang: archive/tar: Unbounded allocation when parsing GNU sparse map github.com/containerd/containerd: containerd: Memory exhaustion via CRI Attach implementation goroutine leaks node-forge: node-forge ASN.1 Unbounded Recursion urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion urllib3: urllib3 Streaming API improperly handles highly compressed data github.com/sigstore/fulcio: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;github.com/containerd/containerd: containerd local privilege escalation node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications lodash: prototype pollution in _.unset and _.omit functions qs: qs: Denial of Service via improper input validation in array parsing runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects golang: archive/tar: Unbounded allocation when parsing GNU sparse map github.com/containerd/containerd: containerd: Memory exhaustion via CRI Attach implementation goroutine leaks node-forge: node-forge ASN.1 Unbounded Recursion urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion urllib3: urllib3 Streaming API improperly handles highly compressed data github.com/sigstore/fulcio: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:2900</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:21042-1 — Security update for containerd</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:21042-1</link>
      <description>&lt;p&gt;Security update for containerd&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for containerd&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:21042-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-64329</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-64329</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: containerd, Ubuntu:Pro:18.04:LTS: containerd, Ubuntu:Pro:20.04:LTS: containerd, Ubuntu:Pro:20.04:LTS: containerd-app, Ubuntu:22.04:LTS: containerd, Ubuntu:Pro:22.04:LTS: containerd-app, Ubuntu:24.04:LTS: containerd-app, Ubuntu:Pro:24.04:LTS: containerd, Ubuntu:25.10: containerd, Ubuntu:25.10: containerd-app&lt;/p&gt;
&lt;p&gt;containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4, and 2.2.0-beta.0 through 2.2.0-rc.1 contain a bug in the CRI Attach implementation where a user can exhaust memory on the host due to goroutine leaks. This issue is fixed in versions 1.7.29, 2.0.7, 2.1.5 and 2.2.0. To workaround this vulnerability, users can set up an admission controller to control accesses to pods/attach resources.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: containerd, Ubuntu:Pro:18.04:LTS: containerd, Ubuntu:Pro:20.04:LTS: containerd, Ubuntu:Pro:20.04:LTS: containerd-app, Ubuntu:22.04:LTS: containerd, Ubuntu:Pro:22.04:LTS: containerd-app, Ubuntu:24.04:LTS: containerd-app, Ubuntu:Pro:24.04:LTS: containerd, Ubuntu:25.10: containerd, Ubuntu:25.10: containerd-app&lt;/p&gt;
&lt;p&gt;containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4, and 2.2.0-beta.0 through 2.2.0-rc.1 contain a bug in the CRI Attach implementation where a user can exhaust memory on the host due to goroutine leaks. This issue is fixed in versions 1.7.29, 2.0.7, 2.1.5 and 2.2.0. To workaround this vulnerability, users can set up an admission controller to control accesses to pods/attach resources.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-64329</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2563 — Microsoft Azure Linux: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2563</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Microsoft Azure Linux und Microsoft Windows ausnutzen um erhöhte Privilegien zu erlangen, beliebigen Code auszuführen, die Authentifizierung zu umgehen,  Spoofing-Angriffe durchzuführen, einen Denial-of-Service-Zustand zu verursachen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Microsoft Azure Linux und Microsoft Windows ausnutzen um erhöhte Privilegien zu erlangen, beliebigen Code auszuführen, die Authentifizierung zu umgehen,  Spoofing-Angriffe durchzuführen, einen Denial-of-Service-Zustand zu verursachen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2563</guid>
    </item>
  </channel>
</rss>
