|
|
Log in / Subscribe / Register

Ubuntu alert USN-8473-1 (containerd-stable)

From:  noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8473-1] containerd-stable vulnerabilities
Date:  Thu, 25 Jun 2026 14:30:15 +0000
Message-ID:  <E1wcl5r-0000F6-3k@lists.ubuntu.com>
Cc:  noreply+usn-bot@canonical.com

========================================================================== Ubuntu Security Notice USN-8473-1 June 25, 2026 containerd-stable vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 Summary: Several security issues were fixed in containerd. Software Description: - containerd-stable: open and reliable container runtime Details: It was discovered that containerd incorrectly handled HTTP/2 SETTINGS frames. A remote attacker could possibly use this issue to cause containerd to enter an infinite loop, resulting in a denial of service. (CVE-2026-33814) Jakub Ciolek and Kyle Elliott discovered that containerd incorrectly handled group parsing when creating containers from images. An attacker could possibly use this issue to cause containerd to consume excessive memory, resulting in a denial of service. (CVE-2026-47262) Henry Beberman and Robert Prast discovered that containerd incorrectly validated image references when importing container checkpoints. An attacker could possibly use this issue to poison the local image cache and execute arbitrary code in other pods. (CVE-2026-50195) Robert Prast discovered that containerd incorrectly propagated labels from image configurations to containers. An attacker could possibly use this issue to execute arbitrary code on the host. (CVE-2026-53488) Yuming Zhang, Song Li, Sangwon Ryu, Henry Beberman, Robert Prast, Kyle Elliott and Zhenchen Wang discovered that containerd incorrectly validated symlinked paths when restoring container checkpoints. An attacker could possibly use this issue to read arbitrary files on the host, resulting in information disclosure. (CVE-2026-53489) Robert Prast discovered that containerd incorrectly trusted device interface annotations when restoring container checkpoints. An attacker could possibly use this issue to bypass resource allocation restrictions and inject devices or host mounts into a container. (CVE-2026-53492) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS containerd-stable 2.2.2-0ubuntu1.1 Ubuntu 25.10 containerd-stable 2.1.6-0ubuntu1~25.10.2 After a standard system update you need to restart containerd to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8473-1 CVE-2026-33814, CVE-2026-47262, CVE-2026-50195, CVE-2026-53488, CVE-2026-53489, CVE-2026-53492 Package Information: https://launchpad.net/ubuntu/+source/containerd-stable/2.... https://launchpad.net/ubuntu/+source/containerd-stable/2....


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmo9Nz0ACgkQcpJm3tlz hgGKgg/9FTxwOtIWEoSIUoYpYF3wZduPTjqdiQG+6XQlypkkrUgW1J296YJPCyxC IEg4bC9zQT3DFLQYonxsL5B8H6jhLSgTp0uh9G3XA3TquIhqylLZ3/SvjXyWG1vO p2PAQrYiX7LDz4ImMQ/zaApLFkh9iV0uee+NcmgIlOIYKxwApvHYvT/BeneMW55J gEwIRz9Yx15QQ8AKBwlebGr+6eIQBtdIdHDXTsUXUXCUCA2vTuB86eBOV6TWB0wP 8Spm8mw456RzLy1dgyNQwWPbDZg8l5rBYcNw4iVBMfMkDQQKH8nfQrOFJLlcoqDk AAmFzrwXUhZE9t/yq+d2mcaFOPeluO6pLdXhXRc2X24GHJ1d3/i+06rCqL8pU2hU GRXge15p3QoLCVpIE8+sJE+rOd14AGEjYcasdilV1ho4ZOlTCJNeuKB1FGTWsoG2 UMKUA9qUX3mBIOfTlusbn/VwRWyIsdbwpgipz0aT6MOawAcgVbYmPcNfFCeZ4Xwc 2aMaafrmVxmjVBEb3CdLsymi+lUqynkHtFGQXDCtIBkbESYK8COTPKXpNdwF4a2k nEnfhuQ8TYffG/SX5SOIUaq33jjv18SzVnTKqlUX9n+M0wpZy0o8McWJjhUhKs/d KnBO91xtLOV1RfA3K552gMZ6TbMw1Dmnlz4sqTL6lV5XagcBe4M= =qEle -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds