Bug 2174473 (CVE-2023-25153) - CVE-2023-25153 containerd: OCI image importer memory exhaustion
Summary: CVE-2023-25153 containerd: OCI image importer memory exhaustion
Keywords:
Status: CLOSED UPSTREAM
Alias: CVE-2023-25153
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2174478 2174480 2174481 2178328
Blocks: 2170820
TreeView+ depends on / blocked
 
Reported: 2023-03-01 18:22 UTC by Anten Skrabec
Modified: 2023-11-08 14:03 UTC (History)
6 users (show)

Fixed In Version: containerd 1.5.18, contained 1.6.18
Clone Of:
Environment:
Last Closed: 2023-03-01 22:16:49 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2023:6817 0 None None None 2023-11-08 14:03:30 UTC

Description Anten Skrabec 2023-03-01 18:22:07 UTC
containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file where a limit was not applied could cause a denial of service. This bug has been fixed in containerd 1.6.18 and 1.5.18. Users should update to these versions to resolve the issue. As a workaround, ensure that only trusted images are used and that only trusted users have permissions to import images.

Comment 1 Anten Skrabec 2023-03-01 18:26:57 UTC
Created containerd tracking bugs for this issue:

Affects: fedora-all [bug 2174478]

Comment 2 Anten Skrabec 2023-03-01 18:28:28 UTC
Created golang-github-moby-buildkit tracking bugs for this issue:

Affects: fedora-36 [bug 2174480]


Created stargz-snapshotter tracking bugs for this issue:

Affects: fedora-all [bug 2174481]

Comment 3 Product Security DevOps Team 2023-03-01 22:16:48 UTC
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.

Comment 5 errata-xmlrpc 2023-11-08 14:03:29 UTC
This issue has been addressed in the following products:

  RHEL-9-CNV-4.14

Via RHSA-2023:6817 https://access.redhat.com/errata/RHSA-2023:6817


Note You need to log in before you can comment on or make changes to this bug.