CVE 6.9 MEDIUM

containerd CRI server: Host memory exhaustion through Attach goroutine leak_CVE-2025-64329

6.9 / 10
MEDIUM
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Description

containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4, and 2.2.0-beta.0 through 2.2.0-rc.1 contain a bug in the CRI Attach implementation where a user can exhaust memory on the host due to goroutine leaks. This issue is fixed in versions 1.7.29, 2.0.7, 2.1.5 and 2.2.0. To workaround this vulnerability, users can set up an admission controller to control accesses to pods/attach resources.

Basic Information

ID CVE-2025-64329
Source GitHub_M
Published Nov 7, 2025 at 04:15

Affected Product

Vendor containerd
Product containerd
Version < 1.7.29
Affected Versions containerd containerd < 1.7.29
containerd containerd < 2.0.7
containerd containerd >= 2.1.0-beta.0, < 2.1.5
containerd containerd >= 2.2.0-beta.0, < 2.2.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.