漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
containerd CRI checkpoint restore CDI annotation smuggling
Vulnerability Description
containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint image metadata during container restoration. When restoring a container from a checkpoint, containerd preserves CDI-related annotations from the checkpoint archive rather than relying solely on the pod's create-time specification. This allows a user with pod creation permissions to bypass standard Kubernetes resource allocation and device plugin enforcement, injecting arbitrary CDI edits (such as device nodes and host mounts) into the restored container. Successful exploitation requires that the node has CDI enabled and contains a matching host CDI specification for the requested device; environments where CDI is disabled or lacking sensitive device specifications are not affected. This issue has been fixed in versions 2.3.2, 2.2.5 and 2.1.9.
CVSS Information
N/A
Vulnerability Type
输入验证不恰当
Vulnerability Title
containerd 输入验证错误漏洞
Vulnerability Description
containerd containerd是containerd团队的一款容器运行环境软件。 containerd 2.3.2之前版本、2.2.5之前版本和2.1.9之前版本存在安全漏洞,该漏洞源于CRI实现不当信任容器恢复期间来自不受信任检查点镜像元数据中的Container Device Interface注释,可能导致具有Pod创建权限的用户绕过标准Kubernetes资源分配和设备插件执行,向恢复的容器中注入任意CDI编辑内容。
CVSS Information
N/A
Vulnerability Type
N/A