CVE-2025-64329 Details
Description
containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4, and 2.2.0-beta.0 through 2.2.0-rc.1 contain a bug in the CRI Attach implementation where a user can exhaust memory on the host due to goroutine leaks. This issue is fixed in versions 1.7.29, 2.0.7, 2.1.5 and 2.2.0. To workaround this vulnerability, users can set up an admission controller to control accesses to pods/attach resources.
A memory exhaustion vulnerability has been identified in containerd versions 1.7.28 and prior, as well as in the 2.0.0-beta.0 to 2.0.6, 2.1.0-beta.0 to 2.1.4, and 2.2.0-beta.0 to 2.2.0-rc.1 releases. The issue arises from goroutine leaks in the CRI Attach functionality, allowing a user to deplete host memory. This vulnerability can be exploited by making repeated CRI Attach calls, such as through 'kubectl attach', which could lead to increased memory consumption by containerd.
Users can update to containerd versions 1.7.29, 2.0.7, 2.1.5, or 2.2.0 to address this vulnerability. Additionally, an admission controller can be set up to manage access to 'pods/attach' resources as a temporary workaround.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-401 | Missing Release of Memory after Effective Lifetime | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linuxfoundation containerd | < 1.7.29 >= 2.0.0, < 2.0.7 >= 2.1.0, < 2.1.5 2.2.0 beta0 2.2.0 beta1 2.2.0 beta2 2.2.0 rc0 2.2.0 rc1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 31, 2025 | Initial Analysis | [email protected] |
| Nov 7, 2025 | New CVE Received | [email protected] |