containerd is an open-source container runtime. A bug was found in
containerd prior to versions 1.6.38, 1.7.27, and 2.0.4 where containers
launched with a User set as a `UID:GID` larger than the maximum 32-bit
signed integer can cause an overflow condition where the container
ultimately runs as root (UID 0). This could cause unexpected behavior
for environments that require containers to run as a non-root user. This
bug has been fixed in containerd 1.6.38, 1.7.27, and 2.04. As a
workaround, ensure that only trusted images are used and that only
trusted users have permissions to import images.
- https://bugs.mageia.org/show_bug.cgi?id=34145
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IAMUEOAZJQQS6MSFKLEO72TDYAONTTXF/
- https://www.cve.org/CVERecord?id=CVE-2024-40635
- 9/core/docker-containerd-1.7.27-1.mga9
Get the latest Linux and open source security news straight to your inbox.