Executive brief
The containerd CRI Plugin is a core component that manages container lifecycles in Kubernetes and container orchestration systems. Multiple vulnerabilities in this plugin could allow attackers to escalate privileges, potentially giving them control over containerized workloads and the underlying host system. This poses a significant risk to containerized environments and the applications running within them.
Technical details
The containerd CRI (Container Runtime Interface) Plugin manages container lifecycle operations in Kubernetes environments. Multiple privilege escalation vulnerabilities have been identified in this component (tracked under five CVE identifiers). While specific technical details are limited in the advisory, these vulnerabilities likely involve issues in the plugin's handling of container operations, resource constraints, or permission boundaries. The attack vector appears to be network or local depending on the specific vulnerability. Exploitation could allow authenticated users or local attackers to escalate privileges within or outside container sandboxes. Patches or updates should be applied to affected containerd versions.
Affected products
- containerd containerd
Timeline
- 2026-09-22: disclosed