Bug 2413190 (CVE-2024-25621) - CVE-2024-25621 github.com/containerd/containerd: containerd local privilege escalation
Summary: CVE-2024-25621 github.com/containerd/containerd: containerd local privilege e...
Keywords:
Status: NEW
Alias: CVE-2024-25621
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2418984 2418986 2418987 2418988 2418990 2418992 2418993 2418995 2418997 2418998 2418999 2419000 2419001 2419002 2419003 2419007 2419008 2419009 2419010 2419011 2419012 2419013 2419014 2419018 2419020 2419021 2419023 2419024 2419027 2419028 2419029 2419030 2419031 2419032 2419036 2419037 2419038 2419039 2419040 2419045 2419047 2419049 2419050 2419062 2419959 2418985 2418989 2418994 2418996 2419004 2419005 2419006 2419015 2419016 2419017 2419019 2419022 2419025 2419026 2419033 2419034 2419035 2419041 2419042 2419043 2419044 2419046 2419048 2419051 2419425 2419426 2419427 2419428 2419429 2419430 2419431 2419432 2419433 2419434 2419435 2419436 2419437 2419438 2419439 2419440 2419441 2419442 2419443 2419444 2419445 2419446 2419447 2419448 2419449 2419450 2419451 2419452
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-11-06 19:01 UTC by OSIDB Bzimport
Modified: 2025-12-08 07:47 UTC (History)
119 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-11-06 19:01:43 UTC
containerd is an open-source container runtime. Versions 0.1.0 through 1.7.28, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4 and 2.2.0-beta.0 through 2.2.0-rc.1 have an overly broad default permission vulnerability. Directory paths `/var/lib/containerd`, `/run/containerd/io.containerd.grpc.v1.cri` and `/run/containerd/io.containerd.sandbox.controller.v1.shim` were all created with incorrect permissions. This issue is fixed in versions 1.7.29, 2.0.7, 2.1.5 and 2.2.0. Workarounds include updating system administrator permissions so the host can manually chmod the directories to not have group or world accessible permissions, or to run containerd in rootless mode.


Note You need to log in before you can comment on or make changes to this bug.