CVE-2023-25153
Summary
| CVE | CVE-2023-25153 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-16 15:15:00 UTC |
| Updated | 2023-11-07 04:08:00 UTC |
| Description | containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file where a limit was not applied could cause a denial of service. This bug has been fixed in containerd 1.6.18 and 1.5.18. Users should update to these versions to resolve the issue. As a workaround, ensure that only trusted images are used and that only trusted users have permissions to import images. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| OCI image importer memory exhaustion · Advisory · containerd/containerd · GitHub |
MISC |
github.com |
|
| Release containerd 1.6.18 · containerd/containerd · GitHub |
MISC |
github.com |
|
| Merge pull request from GHSA-259w-8hf6-59c2 · containerd/containerd@0c31490 · GitHub |
MISC |
github.com |
|
| Release containerd 1.5.18 · containerd/containerd · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181860 Debian Security Update for containerd (CVE-2023-25153)
- 199448 Ubuntu Security Notification for containerd Vulnerabilities (USN-6202-1)
- 283789 Fedora Security Update for stargz (FEDORA-2023-ee472c698c)
- 283793 Fedora Security Update for containerd (FEDORA-2023-aadd08ab96)
- 283794 Fedora Security Update for containerd (FEDORA-2023-05b39bc048)
- 284254 Fedora Security Update for stargz (FEDORA-2023-62ce942e75)
- 284257 Fedora Security Update for containerd (FEDORA-2023-cd000ea847)
- 354880 Amazon Linux Security Advisory for containerd : ALAS2DOCKER-2023-023
- 354881 Amazon Linux Security Advisory for containerd : ALAS2NITRO-ENCLAVES-2023-023
- 355215 Amazon Linux Security Advisory for containerd : ALAS2023-2023-156
- 355315 Amazon Linux Security Advisory for containerd : ALAS2ECS-2023-002
- 357051 Amazon Linux Security Advisory for containerd : ALAS2DOCKER-2024-035
- 357058 Amazon Linux Security Advisory for containerd : ALAS2NITRO-ENCLAVES-2024-035
- 502839 Alpine Linux Security Update for containerd
- 6140059 AWS Bottlerocket Security Update for containerd (GHSA-pp3v-5483-gc93)
- 672859 EulerOS Security Update for docker-engine (EulerOS-SA-2023-1591)
- 672969 EulerOS Security Update for docker-engine (EulerOS-SA-2023-1837)
- 672971 EulerOS Security Update for docker-engine (EulerOS-SA-2023-1864)
- 673024 EulerOS Security Update for docker-engine (EulerOS-SA-2023-1971)
- 673027 EulerOS Security Update for docker-engine (EulerOS-SA-2023-1949)
- 673082 EulerOS Security Update for docker-engine (EulerOS-SA-2023-2142)
- 673137 EulerOS Security Update for containerd (EulerOS-SA-2023-2285)
- 673146 EulerOS Security Update for containerd (EulerOS-SA-2023-2261)
- 905563 Common Base Linux Mariner (CBL-Mariner) Security Update for moby-engine (13584)
- 905566 Common Base Linux Mariner (CBL-Mariner) Security Update for k3s (13571)
- 905573 Common Base Linux Mariner (CBL-Mariner) Security Update for moby-containerd (13608)
- 905615 Common Base Linux Mariner (CBL-Mariner) Security Update for moby-containerd (13674)
- 906544 Common Base Linux Mariner (CBL-Mariner) Security Update for moby-containerd (13608-1)
- 906558 Common Base Linux Mariner (CBL-Mariner) Security Update for moby-containerd (13608-3)
- 906620 Common Base Linux Mariner (CBL-Mariner) Security Update for moby-engine (13584-3)
- 906664 Common Base Linux Mariner (CBL-Mariner) Security Update for moby-containerd (13674-3)
- 906802 Common Base Linux Mariner (CBL-Mariner) Security Update for moby-containerd (13608-5)