More information about this security flaw is available in the following bug: https://bugzilla.redhat.com/show_bug.cgi?id=2367631 Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The affected version of containerd is v2.1.0 (see https://github.com/containerd/containerd/security/advisories/GHSA-cm76-qm8v-3j95). Fedora 42 deploys containerd v2.0.5 at this time. This vulnerability does affect containerd in rawhide and a fix will be deployed on 20 and 21 May 2025.