Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2022-23648 Details

Description

containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.14.12 where containers launched through containerd’s CRI implementation on Linux with a specially-crafted image configuration could gain access to read-only copies of arbitrary files and directories on the host. This may bypass any policy-based enforcement on container setup (including a Kubernetes Pod Security Policy) and expose potentially sensitive information. Kubernetes and crictl can both be configured to use containerd’s CRI implementation. This bug has been fixed in containerd 1.6.1, 1.5.10, and 1.4.12. Users should update to these versions to resolve the issue.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
http://packetstormsecurity.com/files/166421/containerd-Image-Volume-Insecure-Handling.html CVEExploitThird Party AdvisoryVDB Entry
https://github.com/containerd/containerd/commit/10f428dac7cec44c864e1b830a4623af27a9fc70 CVEPatchThird Party Advisory
https://github.com/containerd/containerd/releases/tag/v1.4.13 CVEPatchRelease NotesThird Party Advisory
https://github.com/containerd/containerd/releases/tag/v1.5.10 CVEPatchRelease NotesThird Party Advisory
https://github.com/containerd/containerd/releases/tag/v1.6.1 CVEPatchRelease NotesThird Party Advisory

see all 22 references

Weakness Enumeration

CWE-IDCWE NameSource
NVD-CWE-noinfoInsufficient Information to Classify Weakness[email protected]
CWE-200Exposure of Sensitive Information to an Unauthorized Actor[email protected]

Affected Products

ProductVersions
linuxfoundation containerd
< 1.4.13
>= 1.5.0, < 1.5.10
>= 1.6.0, < 1.6.1

CPE

  • cpe:2.3:a:linuxfoundation:containerd:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
debian debian linux
11.0

CPE

  • cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
fedoraproject fedora
34
35
36

CPE

  • cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

14 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2022-23648
NVD Published Date:
Mar 3, 2022
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2022-23648 Details - Not Deferred