QID 198300

Date Published: 2021-03-31

QID 198300: Ubuntu Security Notification for Containerd Vulnerability (USN-4881-1)

It was discovered that containerd incorrectly handled certain environment variables.

Contrary to expectations, a container could receive environment variables defined for a different container, possibly containing sensitive information.

  • CVSS V3 rated as High - 6.3 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Refer to Ubuntu advisory USN-4881-1 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 198300

    Software Advisories
    Advisory ID Software Component Link
    USN-4881-1 20.04 (focal) on src containerd URL Logo launchpad.net/ubuntu/+source/containerd/1.3.3-0ubuntu2.3
    USN-4881-1 20.10 (groovy) on src containerd URL Logo launchpad.net/ubuntu/+source/containerd/1.3.7-0ubuntu3.3