Logo
vulnerabilityCVE-2024-40635
Name
CVE-2024-40635
Source
NVD ( link)Debian ( link)
Description
containerd is an open-source container runtime. A bug was found in containerd prior to versions 1.6.38, 1.7.27, and 2.0.4 where containers launched with a User set as a `UID:GID` larger than the maximum 32-bit signed integer can cause an overflow condition where the container ultimately runs as root (UID 0). This could cause unexpected behavior for environments that require containers to run as a non-root user. This bug has been fixed in containerd 1.6.38, 1.7.27, and 2.04. As a workaround, ensure that only trusted images are used and that only trusted users have permissions to import images.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
containerd
Exploitable

Vulnerability Ratings#


4.6
CVSSv31
7.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.0.7
Not Affected
buildroot
master
2.0.7
Not Affected
openwrt
master
2.2.3-r1
Not Affected