
Cloud Vulnerability DB
A community-led vulnerabilities database
A bug was found in containerd versions prior to 1.4.8 and 1.5.4 where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing files in the host's filesystem (GitHub Advisory, NVD).
The vulnerability exists in the archive package of containerd where file permission changes can affect files outside of the unpack target directory. The issue allows changes to file permissions that can deny access to the expected owner of the file, widen access to others, or set extended bits like setuid, setgid, and sticky. This vulnerability does not directly allow files to be read, modified, or executed without an additional cooperating process (GitHub Advisory).
The vulnerability can result in unauthorized file permission modifications on the host system. Changes to file permissions can deny access to the expected owner of the file, widen access to others, or set extended bits like setuid, setgid, and sticky bits on existing files in the host's filesystem (GitHub Advisory, Ubuntu Security).
The vulnerability can be exploited if a user or automated system is tricked into launching a specially crafted container image. The exploitation does not directly allow files to be read, modified, or executed without an additional cooperating process (Ubuntu Security).
Users should update to containerd versions 1.5.4 or 1.4.8 or later. Running containers do not need to be restarted. As a workaround, users should ensure they only pull images from trusted sources. Linux security modules (LSMs) like SELinux and AppArmor can limit the files potentially affected through policies and profiles that prevent containerd from interacting with unexpected files (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."