Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-25153
HistoryFeb 16, 2023 - 3:15 p.m.

Design/Logic Flaw

2023-02-1615:15:00
PRIOn knowledge base
www.prio-n.com
13
containerd
open source
runtime
vulnerability fix
denial of service
trusted images
trusted users
nvd

6.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

20.7%

containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file where a limit was not applied could cause a denial of service. This bug has been fixed in containerd 1.6.18 and 1.5.18. Users should update to these versions to resolve the issue. As a workaround, ensure that only trusted images are used and that only trusted users have permissions to import images.