CVE-2026-53489 Details
Description
containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a bug where the CRI plugin restores container.log from a checkpoint image without validating a symlinked path. This could result in reading an arbitrary file on the host via kubectl logs. This issue has been fixed in versions 2.3.2, 2.2.5 and 2.1.9.
A vulnerability in containerd, an open-source container runtime, allows for arbitrary file reading on the host. This issue exists in versions 2.1.0 prior to 2.1.9, 2.2.0 prior to 2.2.5, and 2.3.0 prior to 2.3.2. The vulnerability arises because the CRI plugin restores 'container.log' from a checkpoint image without validating symlinked paths, potentially leading to unauthorized file access through 'kubectl logs'.
Users are advised to update to containerd versions 2.3.2, 2.2.5, or 2.1.9. For more information, consult the containerd GitHub repository or contact the containerd security team.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/containerd/containerd/security/advisories/GHSA-rgh6-rfwx-v388 | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-61 | UNIX Symbolic Link (Symlink) Following | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linuxfoundation containerd | >= 2.1.0, < 2.1.9 >= 2.2.0, < 2.2.5 >= 2.3.0, < 2.3.2 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 2, 2026 | Initial Analysis | [email protected] |
| Jul 2, 2026 | CVE Modified | CISA-ADP |
| Jul 1, 2026 | New CVE Received | [email protected] |