containerd CRI plugin: Host memory exhaustion through ExecSync
Description
containerd is an open source container runtime. A bug was found in the containerd's CRI implementation where programs inside a container can cause the containerd daemon to consume memory without bound during invocation of the ExecSync API. This can cause containerd to consume all available memory on the computer, denying service to other legitimate workloads. Kubernetes and crictl can both be configured to use containerd's CRI implementation; ExecSync may be used when running probes or when executing processes via an "exec" facility. This bug has been fixed in containerd 1.6.6 and 1.5.13. Users should update to these versions to resolve the issue. Users unable to upgrade should ensure that only trusted images and commands are used.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/containerd/containerdGo | < 1.5.13 | 1.5.13 |
github.com/containerd/containerdGo | >= 1.6.0, < 1.6.6 | 1.6.6 |
Affected products
87- osv-coords86 versionspkg:apk/chainguard/ctoppkg:apk/wolfi/ctoppkg:golang/github.com/containerd/containerdpkg:rpm/opensuse/containerd&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/containerd&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/containerd&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/docker&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/docker&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/docker-kubic&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/docker-kubic&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/runc&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/runc&distro=openSUSE%20Leap%2015.4pkg:rpm/suse/containerd&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/containerd&distro=SUSE%20Enterprise%20Storage%207pkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOSpkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2012pkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP3pkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP4pkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP3pkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-BCLpkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/containerd&distro=SUSE%20Manager%20Proxy%204.1pkg:rpm/suse/containerd&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.1pkg:rpm/suse/containerd&distro=SUSE%20Manager%20Server%204.1pkg:rpm/suse/docker&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/docker&distro=SUSE%20Enterprise%20Storage%207pkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOSpkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2012pkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP3pkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP4pkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-BCLpkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/docker&distro=SUSE%20Manager%20Proxy%204.1pkg:rpm/suse/docker&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.1pkg:rpm/suse/docker&distro=SUSE%20Manager%20Server%204.1pkg:rpm/suse/runc&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/runc&distro=SUSE%20Enterprise%20Storage%207pkg:rpm/suse/runc&distro=SUSE%20Enterprise%20Storage%207.1pkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOSpkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2012pkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP3pkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP4pkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-BCLpkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/runc&distro=SUSE%20Manager%20Proxy%204.1pkg:rpm/suse/runc&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.1pkg:rpm/suse/runc&distro=SUSE%20Manager%20Server%204.1
< 0.7.7-r13+ 85 more
- (no CPE)range: < 0.7.7-r13
- (no CPE)range: < 0.7.7-r13
- (no CPE)range: < 1.5.13
- (no CPE)range: < 1.6.6-150000.73.2
- (no CPE)range: < 1.6.6-150000.73.2
- (no CPE)range: < 1.6.6-1.1
- (no CPE)range: < 20.10.17_ce-150000.166.1
- (no CPE)range: < 20.10.17_ce-150000.166.1
- (no CPE)range: < 20.10.17_ce-150000.166.1
- (no CPE)range: < 20.10.17_ce-150000.166.1
- (no CPE)range: < 1.1.3-150000.30.1
- (no CPE)range: < 1.1.3-150000.30.1
- (no CPE)range: < 1.6.6-150000.73.2
- (no CPE)range: < 1.6.6-150000.73.2
- (no CPE)range: < 1.6.6-150000.73.2
- (no CPE)range: < 1.6.6-150000.73.2
- (no CPE)range: < 1.6.6-150000.73.2
- (no CPE)range: < 1.6.6-150000.73.2
- (no CPE)range: < 1.6.6-150000.73.2
- (no CPE)range: < 1.6.6-150000.73.2
- (no CPE)range: < 1.6.6-150000.73.2
- (no CPE)range: < 1.6.6-150000.73.2
- (no CPE)range: < 1.6.6-16.62.1
- (no CPE)range: < 1.6.6-150000.73.2
- (no CPE)range: < 1.6.6-150000.73.2
- (no CPE)range: < 1.6.6-150000.73.2
- (no CPE)range: < 1.6.6-150000.73.2
- (no CPE)range: < 1.6.6-150000.73.2
- (no CPE)range: < 1.6.6-150000.73.2
- (no CPE)range: < 1.6.6-150000.73.2
- (no CPE)range: < 1.6.6-150000.73.2
- (no CPE)range: < 1.6.6-150000.73.2
- (no CPE)range: < 1.6.6-150000.73.2
- (no CPE)range: < 1.6.6-150000.73.2
- (no CPE)range: < 1.6.6-150000.73.2
- (no CPE)range: < 1.6.6-150000.73.2
- (no CPE)range: < 1.6.6-150000.73.2
- (no CPE)range: < 20.10.17_ce-150000.166.1
- (no CPE)range: < 20.10.17_ce-150000.166.1
- (no CPE)range: < 20.10.17_ce-150000.166.1
- (no CPE)range: < 20.10.17_ce-150000.166.1
- (no CPE)range: < 20.10.17_ce-150000.166.1
- (no CPE)range: < 20.10.17_ce-150000.166.1
- (no CPE)range: < 20.10.17_ce-150000.166.1
- (no CPE)range: < 20.10.17_ce-150000.166.1
- (no CPE)range: < 20.10.17_ce-150000.166.1
- (no CPE)range: < 20.10.17_ce-150000.166.1
- (no CPE)range: < 20.10.17_ce-98.83.1
- (no CPE)range: < 20.10.17_ce-150000.166.1
- (no CPE)range: < 20.10.17_ce-150000.166.1
- (no CPE)range: < 20.10.17_ce-150000.166.1
- (no CPE)range: < 20.10.17_ce-150000.166.1
- (no CPE)range: < 20.10.17_ce-150000.166.1
- (no CPE)range: < 20.10.17_ce-150000.166.1
- (no CPE)range: < 20.10.17_ce-150000.166.1
- (no CPE)range: < 20.10.17_ce-150000.166.1
- (no CPE)range: < 20.10.17_ce-150000.166.1
- (no CPE)range: < 20.10.17_ce-150000.166.1
- (no CPE)range: < 20.10.17_ce-150000.166.1
- (no CPE)range: < 20.10.17_ce-150000.166.1
- (no CPE)range: < 20.10.17_ce-150000.166.1
- (no CPE)range: < 1.1.3-150000.30.1
- (no CPE)range: < 1.1.3-150000.30.1
- (no CPE)range: < 1.1.3-150000.30.1
- (no CPE)range: < 1.1.3-150000.30.1
- (no CPE)range: < 1.1.3-150000.30.1
- (no CPE)range: < 1.1.3-150000.30.1
- (no CPE)range: < 1.1.3-150000.30.1
- (no CPE)range: < 1.1.3-150000.30.1
- (no CPE)range: < 1.1.3-150000.30.1
- (no CPE)range: < 1.1.3-150000.30.1
- (no CPE)range: < 1.1.3-150000.30.1
- (no CPE)range: < 1.1.3-16.21.1
- (no CPE)range: < 1.1.3-150000.30.1
- (no CPE)range: < 1.1.3-150000.30.1
- (no CPE)range: < 1.1.3-150000.30.1
- (no CPE)range: < 1.1.3-150000.30.1
- (no CPE)range: < 1.1.3-150000.30.1
- (no CPE)range: < 1.1.3-150000.30.1
- (no CPE)range: < 1.1.3-150000.30.1
- (no CPE)range: < 1.1.3-150000.30.1
- (no CPE)range: < 1.1.3-150000.30.1
- (no CPE)range: < 1.1.3-150000.30.1
- (no CPE)range: < 1.1.3-150000.30.1
- (no CPE)range: < 1.1.3-150000.30.1
- (no CPE)range: < 1.1.3-150000.30.1
- Range: < 1.5.13
Patches
Vulnerability mechanics
References
13- github.com/advisories/GHSA-5ffw-gxpp-mxpfghsaADVISORY
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/REOZCUAPCA7NFDWYBDYX6EYXWLHABKBO/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WSIGDBHAB3I75JBJNGWEPBTJPS2FOVHD/mitrevendor-advisory
- nvd.nist.gov/vuln/detail/CVE-2022-31030ghsaADVISORY
- security.gentoo.org/glsa/202401-31ghsavendor-advisoryWEB
- www.debian.org/security/2022/dsa-5162ghsavendor-advisoryWEB
- www.openwall.com/lists/oss-security/2022/06/07/1ghsamailing-listWEB
- github.com/containerd/containerd/commit/c1bcabb4541930f643aa36a2b38655e131346382ghsaWEB
- github.com/containerd/containerd/security/advisories/GHSA-5ffw-gxpp-mxpfghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/REOZCUAPCA7NFDWYBDYX6EYXWLHABKBOghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WSIGDBHAB3I75JBJNGWEPBTJPS2FOVHDghsaWEB
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/REOZCUAPCA7NFDWYBDYX6EYXWLHABKBOghsaWEB
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WSIGDBHAB3I75JBJNGWEPBTJPS2FOVHDghsaWEB
News mentions
0No linked articles in our index yet.