CVE-2024-25621
Overly broad default permission vulnerability. Directory paths
`/var/lib/containerd`, `/run/containerd/io.containerd.grpc.v1.cri`
and `/run/containerd/io.containerd.sandbox.controller.v1.shim` were
all created with incorrect permissions.
CVE-2025-64329
Bug in the CRI Attach implementation where a user can exhaust memory
on the host due to goroutine leaks.
For Debian 11 bullseye, these problems have been fixed in version
1.4.13~ds1-1~deb11u6.
We recommend that you upgrade your containerd packages.
For the detailed security status of containerd please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/containerd
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
Get the latest Linux and open source security news straight to your inbox.