Search CVE reports


Toggle filters

1 – 10 of 38 results


CVE-2026-53493

Medium priority
Needs evaluation

containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI index graph can force very high CPU/memory usage during PullImage (before container start), causing long...

3 affected packages

containerd, containerd-app, containerd-stable

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
containerd Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
containerd-app Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
containerd-stable Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-53495

Medium priority
Needs evaluation

containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine...

3 affected packages

containerd, containerd-app, containerd-stable

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
containerd Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
containerd-app Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
containerd-stable Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-46680

Medium priority
Vulnerable

containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a...

3 affected packages

containerd, containerd-app, containerd-stable

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
containerd Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
containerd-app Vulnerable Vulnerable Vulnerable Vulnerable —
containerd-stable Vulnerable Not in release Not in release — —
Show less packages

CVE-2026-53492

High priority
Fixed

containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint image metadata...

3 affected packages

containerd, containerd-app, containerd-stable

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
containerd Not affected Not affected Not affected Not affected Not affected
containerd-app Fixed Fixed Fixed Not affected —
containerd-stable Fixed Not in release Not in release — —
Show less packages

CVE-2026-53489

High priority
Fixed

containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a bug where the CRI plugin restores container.log from a checkpoint image without validating a symlinked path. This could result in...

3 affected packages

containerd, containerd-app, containerd-stable

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
containerd Not affected Not affected Not affected Not affected Not affected
containerd-app Fixed Fixed Fixed Not affected —
containerd-stable Fixed Not in release Not in release — —
Show less packages

CVE-2026-53488

High priority

Some fixes available 12 of 13

containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without...

3 affected packages

containerd, containerd-app, containerd-stable

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
containerd Fixed Fixed Fixed Fixed Fixed
containerd-app Fixed Fixed Fixed Fixed —
containerd-stable Fixed Not in release Not in release — —
Show less packages

CVE-2026-50195

High priority
Fixed

containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the CRI checkpoint import process where it fails to validate the image references specified within a checkpoint...

3 affected packages

containerd, containerd-app, containerd-stable

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
containerd Not affected Not affected Not affected Not affected Not affected
containerd-app Fixed Fixed Fixed Not affected —
containerd-stable Fixed Not in release Not in release — —
Show less packages

CVE-2026-47262

Medium priority

Some fixes available 13 of 14

containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vulnerability that allows a maliciously crafted image to cause a Denial of Service (DoS) condition. When creating...

3 affected packages

containerd, containerd-app, containerd-stable

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
containerd Fixed Fixed Fixed Fixed Fixed
containerd-app Fixed Fixed Fixed Fixed —
containerd-stable Fixed Not in release Not in release — —
Show less packages

CVE-2026-39821

High priority

Some fixes available 2 of 25

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This...

7 affected packages

golang-golang-x-net, google-guest-agent, containerd, adsys, juju-core...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-golang-x-net Needs evaluation Needs evaluation Needs evaluation Not in release Not in release
google-guest-agent Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
containerd Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
adsys Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
juju-core — — — — —
lxd — — — Needs evaluation Needs evaluation
golang-golang-x-net-dev Not in release Not in release Not in release Fixed Fixed
Show all 7 packages Show less packages

CVE-2026-33814

Medium priority

Some fixes available 16 of 34

When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.

9 affected packages

golang-golang-x-net, google-guest-agent, containerd, adsys, containerd-app...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-golang-x-net Vulnerable Vulnerable Vulnerable — —
google-guest-agent Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
containerd Not affected Not affected Fixed Fixed Fixed
adsys Fixed Fixed Fixed Fixed —
containerd-app Fixed Fixed Fixed Fixed —
containerd-stable Fixed Not in release Not in release — —
golang-golang-x-net-dev Not in release Not in release Not in release Needs evaluation Needs evaluation
juju-core Not in release Not in release Not in release — —
lxd Not in release Not in release Not in release Needs evaluation Needs evaluation
Show all 9 packages Show less packages