Bug 2367666
Summary: | CVE-2025-47290 containerd: Containerd vulnerable to host filesystem access during image unpack [fedora-42] | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Jon Moroney <jmoroney> |
Component: | containerd | Assignee: | Brad Smith <bradley.g.smith> |
Status: | CLOSED NOTABUG | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | 42 | CC: | bradley.g.smith, carlos.sepulveda, copper_fin, go-sig, maxwell |
Target Milestone: | --- | Keywords: | Security, SecurityTracking |
Target Release: | --- | ||
Hardware: | Unspecified | ||
OS: | Unspecified | ||
Whiteboard: | {"flaws": ["7c7f0c84-6bf2-4a2b-bf21-7e5174455413"]} | ||
Fixed In Version: | Doc Type: | --- | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2025-05-20 23:41:11 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 2367631 |
Description
Jon Moroney
2025-05-20 20:43:42 UTC
The affected version of containerd is v2.1.0 (see https://github.com/containerd/containerd/security/advisories/GHSA-cm76-qm8v-3j95). Fedora 42 deploys containerd v2.0.5 at this time. This vulnerability does affect containerd in rawhide and a fix will be deployed on 20 and 21 May 2025. |