Ubuntu alert USN-8472-1 (containerd-app)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8472-1] containerd vulnerabilities | |
| Date: | Thu, 25 Jun 2026 14:30:07 +0000 | |
| Message-ID: | <E1wcl5j-00009t-3K@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8472-1 June 25, 2026 containerd-app vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in containerd. Software Description: - containerd-app: open and reliable container runtime Details: It was discovered that containerd incorrectly handled HTTP/2 SETTINGS frames. A remote attacker could possibly use this issue to cause containerd to enter an infinite loop, resulting in a denial of service. (CVE-2026-33814) Jakub Ciolek and Kyle Elliott discovered that containerd incorrectly handled group parsing when creating containers from images. An attacker could possibly use this issue to cause containerd to consume excessive memory, resulting in a denial of service. (CVE-2026-47262) Henry Beberman and Robert Prast discovered that containerd incorrectly validated image references when importing container checkpoints. An attacker could possibly use this issue to poison the local image cache and execute arbitrary code in other pods. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-50195) Robert Prast discovered that containerd incorrectly propagated labels from image configurations to containers. An attacker could possibly use this issue to execute arbitrary code on the host. (CVE-2026-53488) Yuming Zhang, Song Li, Sangwon Ryu, Henry Beberman, Robert Prast, Kyle Elliott and Zhenchen Wang discovered that containerd incorrectly validated symlinked paths when restoring container checkpoints. An attacker could possibly use this issue to read arbitrary files on the host, resulting in information disclosure. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-53489) Robert Prast discovered that containerd incorrectly trusted device interface annotations when restoring container checkpoints. An attacker could possibly use this issue to bypass resource allocation restrictions and inject devices or host mounts into a container. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-53492) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS containerd 2.2.2-0ubuntu1.1 Ubuntu 25.10 containerd 2.2.1-0ubuntu1~25.10.2 Ubuntu 24.04 LTS containerd 2.2.1-0ubuntu1~24.04.3 Ubuntu 22.04 LTS containerd 2.2.1-0ubuntu1~22.04.2 Ubuntu 20.04 LTS containerd 1.7.24-0ubuntu1~20.04.2+esm2 Available with Ubuntu Pro After a standard system update you need to restart containerd to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8472-1 CVE-2026-33814, CVE-2026-47262, CVE-2026-50195, CVE-2026-53488, CVE-2026-53489, CVE-2026-53492 Package Information: https://launchpad.net/ubuntu/+source/containerd-app/2.2.2... https://launchpad.net/ubuntu/+source/containerd-app/2.2.1... https://launchpad.net/ubuntu/+source/containerd-app/2.2.1... https://launchpad.net/ubuntu/+source/containerd-app/2.2.1...
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmo9NyIACgkQcpJm3tlz hgH1rBAA1hSxOHfOsQq8Y5ss8cnZAC+wNDo8UoDPtKxbtDKC314dzRDkmKjBvurQ UqHvLh7aJ/4ARkAUe9fNLXQ8nfNXZdzq5OkjUb+WPjnQnfd0JfcCJuMUkCyLlJW3 RFqVy1NKK6gSNQwPFNhiR1uNy1EF7927edeFY5oAyIK55b5EdvAAd/KGldbi6qSO Cg3BOH7C/HAJwl77pUUdPMbv8y/ARcNXr6gvJB55Qm0tiHJZ+1mhJIguFsSn/Z8L ME9LoQtjg2A2pvALOIL0oNz1mDUomhOOjeUWCjNaMAbpsZqev9Hjlj0qphbMQuqt t+cgHWpccMAMZYG/Epx/PuRsuJXW7ptpJqlnNFpXkBKbxpja+3ayixppmh6f4d84 uqEGaLwCxgM1nnmh9TJa37Lq2zJNiyJ9KIQlxckW7fY7X8bQag8hlvIetLU+ghp0 N9bPLYf03LZsE8+YGqdI99U+RUAOeLKY1eRxGlIDFGD4g5GgSsmxHliIssH7QNnP miXVT9BpqfWTWFuWc/DXb4AFARWzjBFPr7y8XvxVjNKuqibBV/OBaSGOd34B5TSd 3bQbm0PPXbfciGhVgq+/uzaq0TQzKl/PgZhwsmVDNvkKGuY4xxF+RWHht2sNzdgv niSzV91+andluXV6DscDZGyFc8gzA0/GuiaXRJtmi55F0OsT2KM= =ByHg -----END PGP SIGNATURE-----
