Bug 2533230 (CVE-2026-53495)

Summary: CVE-2026-53495 github.com/containerd/containerd: containerd: Denial of Service via CRI ExecSync goroutine leak
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: abarbaro, akhatavk, akoudelk, alebedev, alizardo, amctagga, anjoseph, anpicker, ansmith, aoconnor, aos-team-art-private, aprice, aruklets, asdas, bniver, bparees, bsquizza, cmitchel, crizzo, dfreiber, dhanak, dkeler, doconnor, dpaolell, drosa, drow, dschmidt, dsimansk, dymurray, eborisov, eglynn, elicohen, flucifre, gmeno, gparvin, groman, gtanzill, hasun, hoberger, ibolton, jbalunas, jbritton, jburrell, jbuscemi, jcantril, jchui, jdelft, jfula, jhe, jjoyce, jlanda, jmatthew, jmontleo, jowilson, jprabhak, jpretori, jsamir, jschluet, jupierce, kbempah, kingland, kshier, ktsao, lball, lbragsta, lchilton, lgamliel, lgarciaa, lhh, lpele, mbenjamin, mbiarnes, mburns, mgarciac, mhackett, mnovotny, nboldt, ngough, nyancey, oaljalju, oezr, ometelka, pakotvan, pgaikwad, pjindal, ppalepu, ppostler, prdhamdh, psrna, ptisnovs, rekumar, rhaigner, rhel-process-autobot, rjohnson, rojacob, sakbas, sarad, sausingh, sbratsla, sdawley, sfeifer, sghai, sidsharm, simaishi, slucidi, solenoci, sostapov, sprizend, sseago, stcannon, sthirugn, suppawar, syedriko, teagle, thason, tsze, vereddy, veshanka, vkumar, vlaad, vvoronko, watson-tool-maintainers, wenshen, wtam, xdharmai, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in containerd. When the Container Runtime Interface (CRI) plugin is enabled on Linux, repeated use of CRI ExecSync by exec probes or lifecycle hooks can cause goroutines to become indefinitely blocked. This leads to resource exhaustion and can terminate the containerd process, making the container runtime unavailable. This issue specifically affects deployments utilizing containerd's CRI implementation on Linux.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2533720, 2533721, 2533812, 2533814, 2533815, 2533816, 2533818, 2533819, 2533820, 2533821, 2533822, 2533823, 2533824, 2533825, 2533826, 2533827, 2533828, 2533829, 2533831, 2533834, 2533835, 2533833    
Bug Blocks:    

Description OSIDB Bzimport 2026-09-14 17:33:57 UTC
containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine in internal/cri/server/container_execsync.go when CRI ExecSync is used by exec probes or lifecycle hooks that launch long-lived background child processes retaining standard input and output pipes. The input and output drain phase has no default timeout and did not stop when the request context was canceled, so repeated ExecSync invocations can accumulate blocked goroutines and host memory. The resulting resource exhaustion can cause the OOM killer to terminate containerd, leaving the container runtime unavailable until restart. Deployments not using containerd's CRI implementation and containers not running on Linux are not affected. This issue is fixed in versions 1.7.35, 2.0.12, 2.2.8, and 2.3.5.