containerd CRI ExecSync Goroutine Leak Leading to Node-Level Denial of Service
Summary
| CVE | CVE-2026-53495 |
|---|---|
| State | PUBLISHED |
| Assigner | GitHub_M |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-14 18:17:51 UTC |
| Updated | 2026-09-14 18:17:51 UTC |
| Description | containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine in internal/cri/server/container_execsync.go when CRI ExecSync is used by exec probes or lifecycle hooks that launch long-lived background child processes retaining standard input and output pipes. The input and output drain phase has no default timeout and did not stop when the request context was canceled, so repeated ExecSync invocations can accumulate blocked goroutines and host memory. The resulting resource exhaustion can cause the OOM killer to terminate containerd, leaving the container runtime unavailable until restart. Deployments not using containerd's CRI implementation and containers not running on Linux are not affected. This issue is fixed in versions 1.7.35, 2.0.12, 2.2.8, and 2.3.5. |
Risk And Classification
Primary CVSS: v4.0 6.8 MEDIUM from [email protected]
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Problem Types: CWE-400 | CWE-400 CWE-400: Uncontrolled Resource Consumption
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 6.8 | MEDIUM | CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | DECLARED | 6.8 | MEDIUM | CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
CVSS v4.0 Breakdown
Attack Vector
LocalAttack Complexity
LowAttack Requirements
NonePrivileges Required
LowUser Interaction
NoneConfidentiality
NoneIntegrity
NoneAvailability
HighSub Conf.
NoneSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Containerd | Containerd | affected < 1.7.35 | Not specified |
| CNA | Containerd | Containerd | affected >= 2.0.0, < 2.0.12 | Not specified |
| CNA | Containerd | Containerd | affected >= 2.2.0, < 2.2.8 | Not specified |
| CNA | Containerd | Containerd | affected >= 2.3.0, < 2.3.5 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/containerd/containerd/commit/ff39a972369e2f12fae561a58d658bbf... | [email protected] | github.com | |
| github.com/containerd/containerd/commit/5a2a3a759b0d2ad8c821b33c3afc2089... | [email protected] | github.com | |
| github.com/containerd/containerd/security/advisories/GHSA-7jxh-36q5-gcqv | [email protected] | github.com | |
| github.com/containerd/containerd/commit/9ec55f024041d0641f6d79841e45c878... | [email protected] | github.com | |
| github.com/containerd/containerd/commit/eebea8c4c912f44b656c8295c9e6607a... | [email protected] | github.com | |
| github.com/containerd/containerd/releases/tag/v2.0.12 | [email protected] | github.com | |
| github.com/containerd/containerd/releases/tag/v2.2.8 | [email protected] | github.com | |
| github.com/containerd/containerd/commit/22ccf4314d1fe0834f8e28f10d37d530... | [email protected] | github.com | |
| github.com/containerd/containerd/releases/tag/v2.3.5 | [email protected] | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.