### Impact A bug was found in containerd where the CRI plugin propagates labels from an image config (`LABEL` instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. ### Patches This bug has been fixed in the following containerd versions: * 2.3.2 * 2.2.5 * 2.1.9 * 2.0.10 * 1.7.33 Users should update to these versions to resolve the issue. ### Workarounds Ensure that only trusted images are used. ### Credits The containerd project would like to thank Anthropic Research, in collaboration with Claude, the GKE Security Team using Gemini, and Robert Prast (@robertprast) for independently discovering and responsibly disclosing this issue in accordance with the [containerd security policy](https://github.com/containerd/project/blob/main/SECURITY.md). ### For more information If you have any questions or comments about this advisory: * Open an issue in [containerd](https://github.com/containerd/containerd/issues/new/choose) * Email us at [[email protected]](mailto:[email protected]) To report a security issue in containerd: * [Report a new vulnerability](https://github.com/containerd/containerd/security/advisories/new) * Email us at [[email protected]](mailto:[email protected])
### Impact A bug was found in containerd where the CRI plugin propagates labels from an image config (`LABEL` instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. ### Patches This bug has been fixed in the following containerd versions: * 2.3.2 * 2.2.5 * 2.1.9 * 2.0.10 * 1.7.33 Users should update to these versions to resolve the issue. ### Workarounds Ensure that only trusted images are used. ### Credits The containerd project would like to thank Anthropic Research, in collaboration with Claude, the GKE Security Team using Gemini, and Robert Prast (@robertprast) for independently discovering and responsibly disclosing this issue in accordance with the [containerd security policy](https://github.com/containerd/project/blob/main/SECURITY.md). ### For more information If you have any questions or comments about this advisory: * Open an issue in [containerd](https://github.com/containerd/containerd/issues/new/choose) * Email us at [[email protected]](mailto:[email protected]) To report a security issue in containerd: * [Report a new vulnerability](https://github.com/containerd/containerd/security/advisories/new) * Email us at [[email protected]](mailto:[email protected])
Update github.com/containerd/containerd to 1.7.33; github.com/containerd/containerd/v2 to 2.0.10; github.com/containerd/containerd/v2 to 2.1.9; github.com/containerd/containerd/v2 to 2.2.5; github.com/containerd/containerd/v2 to 2.3.2 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scancontainerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull affects github.com/containerd/containerd (go), github.com/containerd/containerd/v2 (go), github.com/containerd/containerd/v2 (go), github.com/containerd/containerd/v2 (go), github.com/containerd/containerd/v2 (go). Severity is critical. ### Impact A bug was found in containerd where the CRI plugin propagates labels from an image config (`LABEL` instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. ### Patches This bug has been fixed in the following containerd versions: * 2.3.2 * 2.2.5 * 2.1.9 * 2.0.10 * 1.7.33 Users should update to these versions to resolve the issue. ### Workarounds Ensure that only trusted images are used. ### Credits The containerd project would like to thank Anthropic Research, in collaboration with Claude, the GKE Security Team using Gemini, and Robert Prast (@robertprast) for independently discovering and responsibly disclosing this issue in accordance with the [containerd security policy](https://github.com/containerd/project/blob/main/SECURITY.md). ### For more information If you have any questions or comments about this advisory: * Open an issue in [containerd](https://github.com/containerd/containerd/issues/new/choose) * Email us at [[email protected]](mailto:[email protected]) To report a security issue in containerd: * [Report a new vulnerability](https://github.com/containerd/containerd/security/advisories/new) * Email us at [[email protected]](mailto:[email protected])
AI coding agents often install or upgrade packages automatically in go. A critical vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| github.com/containerd/containerdgo | >=1.7.0,<1.7.33 | 1.7.33 |
| github.com/containerd/containerd/v2go | >=2.0.0,<2.0.10 | 2.0.10 |
| github.com/containerd/containerd/v2go | >=2.1.0,<2.1.9 | 2.1.9 |
| github.com/containerd/containerd/v2go | >=2.2.0,<2.2.5 | 2.2.5 |
| github.com/containerd/containerd/v2go | >=2.3.0,<2.3.2 | 2.3.2 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardUpdate github.com/containerd/containerd to 1.7.33; github.com/containerd/containerd/v2 to 2.0.10; github.com/containerd/containerd/v2 to 2.1.9; github.com/containerd/containerd/v2 to 2.2.5; github.com/containerd/containerd/v2 to 2.3.2 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scancontainerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull affects github.com/containerd/containerd (go), github.com/containerd/containerd/v2 (go), github.com/containerd/containerd/v2 (go), github.com/containerd/containerd/v2 (go), github.com/containerd/containerd/v2 (go). Severity is critical. ### Impact A bug was found in containerd where the CRI plugin propagates labels from an image config (`LABEL` instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. ### Patches This bug has been fixed in the following containerd versions: * 2.3.2 * 2.2.5 * 2.1.9 * 2.0.10 * 1.7.33 Users should update to these versions to resolve the issue. ### Workarounds Ensure that only trusted images are used. ### Credits The containerd project would like to thank Anthropic Research, in collaboration with Claude, the GKE Security Team using Gemini, and Robert Prast (@robertprast) for independently discovering and responsibly disclosing this issue in accordance with the [containerd security policy](https://github.com/containerd/project/blob/main/SECURITY.md). ### For more information If you have any questions or comments about this advisory: * Open an issue in [containerd](https://github.com/containerd/containerd/issues/new/choose) * Email us at [[email protected]](mailto:[email protected]) To report a security issue in containerd: * [Report a new vulnerability](https://github.com/containerd/containerd/security/advisories/new) * Email us at [[email protected]](mailto:[email protected])
AI coding agents often install or upgrade packages automatically in go. A critical vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| github.com/containerd/containerdgo | >=1.7.0,<1.7.33 | 1.7.33 |
| github.com/containerd/containerd/v2go | >=2.0.0,<2.0.10 | 2.0.10 |
| github.com/containerd/containerd/v2go | >=2.1.0,<2.1.9 | 2.1.9 |
| github.com/containerd/containerd/v2go | >=2.2.0,<2.2.5 | 2.2.5 |
| github.com/containerd/containerd/v2go | >=2.3.0,<2.3.2 | 2.3.2 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard