{"api_version":"1","generated_at":"2026-04-23T02:37:48+00:00","cve":"CVE-2023-25173","urls":{"html":"https://cve.report/CVE-2023-25173","api":"https://cve.report/api/cve/CVE-2023-25173.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-25173","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-25173"},"summary":{"title":"CVE-2023-25173","description":"containerd is an open source container runtime. A bug was found in containerd prior to versions 1.6.18 and 1.5.18 where supplementary groups are not set up properly inside a container. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container. Downstream applications that use the containerd client library may be affected as well.\n\nThis bug has been fixed in containerd v1.6.18 and v.1.5.18. Users should update to these versions and recreate containers to resolve this issue. Users who rely on a downstream application that uses containerd's client library should check that application for a separate advisory and instructions. As a workaround, ensure that the `\"USER $USERNAME\"` Dockerfile instruction is not used. Instead, set the container entrypoint to a value similar to `ENTRYPOINT [\"su\", \"-\", \"user\"]` to allow `su` to properly set up supplementary groups.","state":"PUBLIC","assigner":"security-advisories@github.com","published_at":"2023-02-16 15:15:00","updated_at":"2023-09-15 21:15:00"},"problem_types":["CWE-863"],"metrics":[],"references":[{"url":"https://github.com/advisories/GHSA-fjm8-m7m6-2fjp","name":"https://github.com/advisories/GHSA-fjm8-m7m6-2fjp","refsource":"MISC","tags":[],"title":"Buildah's incorrect handling of the supplementary groups may lead to data disclosure, modification · CVE-2022-2990 · GitHub Advisory Database · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XNF4OLYZRQE75EB5TW5N42FSXHBXGWFE/","name":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XNF4OLYZRQE75EB5TW5N42FSXHBXGWFE/","refsource":"MISC","tags":[],"title":"[SECURITY] Fedora 39 Update: moby-engine-24.0.5-1.fc39 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/containerd/containerd/commit/133f6bb6cd827ce35a5fb279c1ead12b9d21460a","name":"https://github.com/containerd/containerd/commit/133f6bb6cd827ce35a5fb279c1ead12b9d21460a","refsource":"MISC","tags":[],"title":"Merge pull request from GHSA-hmfx-3pcx-653p · containerd/containerd@133f6bb · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZTE4ITXXPIWZEQ4HYQCB6N6GZIMWXDAI/","name":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZTE4ITXXPIWZEQ4HYQCB6N6GZIMWXDAI/","refsource":"MISC","tags":[],"title":"[SECURITY] Fedora 38 Update: moby-engine-24.0.5-1.fc38 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/containerd/containerd/releases/tag/v1.6.18","name":"https://github.com/containerd/containerd/releases/tag/v1.6.18","refsource":"MISC","tags":[],"title":"Release containerd 1.6.18 · containerd/containerd · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LYZOKMMVX4SIEHPJW3SJUQGMO5YZCPHC/","name":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LYZOKMMVX4SIEHPJW3SJUQGMO5YZCPHC/","refsource":"MISC","tags":[],"title":"[SECURITY] Fedora 37 Update: moby-engine-24.0.5-1.fc37 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.benthamsgaze.org/2022/08/22/vulnerability-in-linux-containers-investigation-and-mitigation/","name":"https://www.benthamsgaze.org/2022/08/22/vulnerability-in-linux-containers-investigation-and-mitigation/","refsource":"MISC","tags":[],"title":"Vulnerability in Linux containers – investigation and mitigation – Bentham’s Gaze","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/containerd/containerd/security/advisories/GHSA-hmfx-3pcx-653p","name":"https://github.com/containerd/containerd/security/advisories/GHSA-hmfx-3pcx-653p","refsource":"MISC","tags":[],"title":"Supplementary groups are not set up properly · Advisory · containerd/containerd · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/advisories/GHSA-phjr-8j92-w5v7","name":"https://github.com/advisories/GHSA-phjr-8j92-w5v7","refsource":"MISC","tags":[],"title":"CRI-O incorrect handling of supplementary groups may lead to sensitive information disclosure · CVE-2022-2995 · GitHub Advisory Database · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/advisories/GHSA-4wjj-jwc9-2x96","name":"https://github.com/advisories/GHSA-4wjj-jwc9-2x96","refsource":"MISC","tags":[],"title":"Podman's incorrect handling of the supplementary groups may lead to data disclosure, modification · CVE-2022-2989 · GitHub Advisory Database · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/containerd/containerd/releases/tag/v1.5.18","name":"https://github.com/containerd/containerd/releases/tag/v1.5.18","refsource":"MISC","tags":[],"title":"Release containerd 1.5.18 · containerd/containerd · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/moby/moby/security/advisories/GHSA-rc4r-wh2q-q6c4","name":"https://github.com/moby/moby/security/advisories/GHSA-rc4r-wh2q-q6c4","refsource":"MISC","tags":[],"title":"Security vulnerability relating to supplementary group permissions · Advisory · moby/moby · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-25173","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-25173","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"25173","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"linuxfoundation","cpe5":"containerd","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2023-25173","qid":"161063","title":"Oracle Enterprise Linux Security Update for podman (ELSA-2023-6474)"},{"cve":"CVE-2023-25173","qid":"161105","title":"Oracle Enterprise Linux Security Update for buildah (ELSA-2023-6473)"},{"cve":"CVE-2023-25173","qid":"161175","title":"Oracle Enterprise Linux Security Update for container-tools:ol8 (ELSA-2023-6939)"},{"cve":"CVE-2023-25173","qid":"181846","title":"Debian Security Update for containerd (CVE-2023-25173)"},{"cve":"CVE-2023-25173","qid":"199448","title":"Ubuntu Security Notification for containerd Vulnerabilities (USN-6202-1)"},{"cve":"CVE-2023-25173","qid":"242287","title":"Red Hat Update for buildah (RHSA-2023:6473)"},{"cve":"CVE-2023-25173","qid":"242335","title":"Red Hat Update for podman security (RHSA-2023:6474)"},{"cve":"CVE-2023-25173","qid":"242415","title":"Red Hat Update for container-tools:rhel8 (RHSA-2023:6939)"},{"cve":"CVE-2023-25173","qid":"283789","title":"Fedora Security Update for stargz (FEDORA-2023-ee472c698c)"},{"cve":"CVE-2023-25173","qid":"283793","title":"Fedora Security Update for containerd (FEDORA-2023-aadd08ab96)"},{"cve":"CVE-2023-25173","qid":"283794","title":"Fedora Security Update for containerd (FEDORA-2023-05b39bc048)"},{"cve":"CVE-2023-25173","qid":"284254","title":"Fedora Security Update for stargz (FEDORA-2023-62ce942e75)"},{"cve":"CVE-2023-25173","qid":"284257","title":"Fedora Security Update for containerd (FEDORA-2023-cd000ea847)"},{"cve":"CVE-2023-25173","qid":"285289","title":"Fedora Security Update for moby (FEDORA-2023-b9c1d0e4c5)"},{"cve":"CVE-2023-25173","qid":"354880","title":"Amazon Linux Security Advisory for containerd : ALAS2DOCKER-2023-023"},{"cve":"CVE-2023-25173","qid":"354881","title":"Amazon Linux Security Advisory for containerd : ALAS2NITRO-ENCLAVES-2023-023"},{"cve":"CVE-2023-25173","qid":"355215","title":"Amazon Linux Security Advisory for containerd : ALAS2023-2023-156"},{"cve":"CVE-2023-25173","qid":"355315","title":"Amazon Linux Security Advisory for containerd : ALAS2ECS-2023-002"},{"cve":"CVE-2023-25173","qid":"356384","title":"Amazon Linux Security Advisory for containerd : ALAS2023-2023-374"},{"cve":"CVE-2023-25173","qid":"357051","title":"Amazon Linux Security Advisory for containerd : ALAS2DOCKER-2024-035"},{"cve":"CVE-2023-25173","qid":"357058","title":"Amazon Linux Security Advisory for containerd : ALAS2NITRO-ENCLAVES-2024-035"},{"cve":"CVE-2023-25173","qid":"379641","title":"Alibaba Cloud Linux Security Update for container-tools:rhel8 (ALINUX3-SA-2024:0050)"},{"cve":"CVE-2023-25173","qid":"502839","title":"Alpine Linux Security Update for containerd"},{"cve":"CVE-2023-25173","qid":"6140049","title":"AWS Bottlerocket Security Update for containerd (GHSA-x336-h4c5-wcqv)"},{"cve":"CVE-2023-25173","qid":"672859","title":"EulerOS Security Update for docker-engine (EulerOS-SA-2023-1591)"},{"cve":"CVE-2023-25173","qid":"672969","title":"EulerOS Security Update for docker-engine (EulerOS-SA-2023-1837)"},{"cve":"CVE-2023-25173","qid":"672971","title":"EulerOS Security Update for docker-engine (EulerOS-SA-2023-1864)"},{"cve":"CVE-2023-25173","qid":"673024","title":"EulerOS Security Update for docker-engine (EulerOS-SA-2023-1971)"},{"cve":"CVE-2023-25173","qid":"673027","title":"EulerOS Security Update for docker-engine (EulerOS-SA-2023-1949)"},{"cve":"CVE-2023-25173","qid":"673082","title":"EulerOS Security Update for docker-engine (EulerOS-SA-2023-2142)"},{"cve":"CVE-2023-25173","qid":"673137","title":"EulerOS Security Update for containerd (EulerOS-SA-2023-2285)"},{"cve":"CVE-2023-25173","qid":"673146","title":"EulerOS Security Update for containerd (EulerOS-SA-2023-2261)"},{"cve":"CVE-2023-25173","qid":"755121","title":"SUSE Enterprise Linux Security Update for helm (SUSE-SU-2023:4124-1)"},{"cve":"CVE-2023-25173","qid":"905553","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for moby-containerd (13591)"},{"cve":"CVE-2023-25173","qid":"905559","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for k3s (13570)"},{"cve":"CVE-2023-25173","qid":"905612","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for moby-containerd (13673)"},{"cve":"CVE-2023-25173","qid":"906541","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for moby-containerd (13591-1)"},{"cve":"CVE-2023-25173","qid":"906581","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for moby-containerd (13591-3)"},{"cve":"CVE-2023-25173","qid":"906687","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for moby-containerd (13673-3)"},{"cve":"CVE-2023-25173","qid":"906781","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for moby-containerd (13591-5)"},{"cve":"CVE-2023-25173","qid":"941386","title":"AlmaLinux Security Update for buildah (ALSA-2023:6473)"},{"cve":"CVE-2023-25173","qid":"941399","title":"AlmaLinux Security Update for podman (ALSA-2023:6474)"},{"cve":"CVE-2023-25173","qid":"941481","title":"AlmaLinux Security Update for container-tools:rhel8 (ALSA-2023:6939)"}]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-25173","ASSIGNER":"security-advisories@github.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"containerd is an open source container runtime. A bug was found in containerd prior to versions 1.6.18 and 1.5.18 where supplementary groups are not set up properly inside a container. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container. Downstream applications that use the containerd client library may be affected as well.\n\nThis bug has been fixed in containerd v1.6.18 and v.1.5.18. Users should update to these versions and recreate containers to resolve this issue. Users who rely on a downstream application that uses containerd's client library should check that application for a separate advisory and instructions. As a workaround, ensure that the `\"USER $USERNAME\"` Dockerfile instruction is not used. Instead, set the container entrypoint to a value similar to `ENTRYPOINT [\"su\", \"-\", \"user\"]` to allow `su` to properly set up supplementary groups."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-863: Incorrect Authorization","cweId":"CWE-863"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"containerd","product":{"product_data":[{"product_name":"containerd","version":{"version_data":[{"version_affected":"=","version_value":"< 1.5.18"},{"version_affected":"=","version_value":">= 1.6.0, < 1.6.18"}]}}]}}]}},"references":{"reference_data":[{"url":"https://github.com/containerd/containerd/security/advisories/GHSA-hmfx-3pcx-653p","refsource":"MISC","name":"https://github.com/containerd/containerd/security/advisories/GHSA-hmfx-3pcx-653p"},{"url":"https://github.com/moby/moby/security/advisories/GHSA-rc4r-wh2q-q6c4","refsource":"MISC","name":"https://github.com/moby/moby/security/advisories/GHSA-rc4r-wh2q-q6c4"},{"url":"https://github.com/containerd/containerd/commit/133f6bb6cd827ce35a5fb279c1ead12b9d21460a","refsource":"MISC","name":"https://github.com/containerd/containerd/commit/133f6bb6cd827ce35a5fb279c1ead12b9d21460a"},{"url":"https://github.com/advisories/GHSA-4wjj-jwc9-2x96","refsource":"MISC","name":"https://github.com/advisories/GHSA-4wjj-jwc9-2x96"},{"url":"https://github.com/advisories/GHSA-fjm8-m7m6-2fjp","refsource":"MISC","name":"https://github.com/advisories/GHSA-fjm8-m7m6-2fjp"},{"url":"https://github.com/advisories/GHSA-phjr-8j92-w5v7","refsource":"MISC","name":"https://github.com/advisories/GHSA-phjr-8j92-w5v7"},{"url":"https://github.com/containerd/containerd/releases/tag/v1.5.18","refsource":"MISC","name":"https://github.com/containerd/containerd/releases/tag/v1.5.18"},{"url":"https://github.com/containerd/containerd/releases/tag/v1.6.18","refsource":"MISC","name":"https://github.com/containerd/containerd/releases/tag/v1.6.18"},{"url":"https://www.benthamsgaze.org/2022/08/22/vulnerability-in-linux-containers-investigation-and-mitigation/","refsource":"MISC","name":"https://www.benthamsgaze.org/2022/08/22/vulnerability-in-linux-containers-investigation-and-mitigation/"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZTE4ITXXPIWZEQ4HYQCB6N6GZIMWXDAI/","refsource":"MISC","name":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZTE4ITXXPIWZEQ4HYQCB6N6GZIMWXDAI/"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LYZOKMMVX4SIEHPJW3SJUQGMO5YZCPHC/","refsource":"MISC","name":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LYZOKMMVX4SIEHPJW3SJUQGMO5YZCPHC/"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XNF4OLYZRQE75EB5TW5N42FSXHBXGWFE/","refsource":"MISC","name":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XNF4OLYZRQE75EB5TW5N42FSXHBXGWFE/"}]},"source":{"advisory":"GHSA-hmfx-3pcx-653p","discovery":"UNKNOWN"},"impact":{"cvss":[{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","version":"3.1"}]}},"nvd":{"publishedDate":"2023-02-16 15:15:00","lastModifiedDate":"2023-09-15 21:15:00","problem_types":["CWE-863"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:linuxfoundation:containerd:*:*:*:*:*:*:*:*","versionEndExcluding":"1.5.18","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:linuxfoundation:containerd:*:*:*:*:*:*:*:*","versionStartIncluding":"1.6.0","versionEndExcluding":"1.6.18","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}