Logo
vulnerabilityCVE-2025-64329
Name
CVE-2025-64329
Source
NVD ( link)Debian ( link)
Description
containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4, and 2.2.0-beta.0 through 2.2.0-rc.1 contain a bug in the CRI Attach implementation where a user can exhaust memory on the host due to goroutine leaks. This issue is fixed in versions 1.7.29, 2.0.7, 2.1.5 and 2.2.0. To workaround this vulnerability, users can set up an admission controller to control accesses to pods/attach resources.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
containerd
Exploitable

Vulnerability Ratings#


6.9
CVSSv4
5.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.0.7
Not Affected
buildroot
master
2.0.7
Not Affected
openwrt
master
2.2.3-r1
Not Affected