CVE-2025-47291 Details
Description
containerd is an open-source container runtime. A bug was found in the containerd's CRI implementation where containerd, starting in version 2.0.1 and prior to version 2.0.5, doesn't put usernamespaced containers under the Kubernetes' cgroup hierarchy, therefore some Kubernetes limits are not honored. This may cause a denial of service of the Kubernetes node. This bug has been fixed in containerd 2.0.5+ and 2.1.0+. Users should update to these versions to resolve the issue. As a workaround, disable usernamespaced pods in Kubernetes temporarily.
A bug exists in containerd's Container Runtime Interface (CRI) implementation, specifically in versions 2.0.1 through 2.0.4. The issue arises because containerd fails to place usernamespaced containers within the appropriate cgroup hierarchy for Kubernetes. As a result, certain Kubernetes resource limits are not enforced, potentially leading to a denial-of-service condition on the Kubernetes node.
To address this vulnerability, users should update containerd to version 2.0.5 or later, or to version 2.1.0 or later. As a temporary workaround, usernamespaced pods can be disabled in Kubernetes.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/containerd/containerd/security/advisories/GHSA-cxfp-7pvr-95ff | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linuxfoundation containerd | >= 2.0.1, < 2.0.5 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 19, 2025 | Initial Analysis | [email protected] |
| May 21, 2025 | New CVE Received | [email protected] |