A medium severity vulnerability, identified as CVE-2026-53495 with a CVSS v4 score of 6.8, exists in containerd's CRI ExecSync implementation that allows exec probes and lifecycle hooks with background child processes to indefinitely block containerd's stdio-drain goroutines leading to resource exhaustion and potential node-level denial of service on Linux systems running containerd with the CRI plugin enabled. This flaw is exploitable via the CRI plugin, requiring low privileges for an attacker to launch long-lived background child processes against a container. The affected versions include those prior to 2.0.12, 1.7.35, and between 2.2.0 and 2.2.8, as well as 2.3.0 and 2.3.5. Users not utilizing the CRI implementation or running containers on Linux are unaffected. This issue can cause containerd to leak goroutines and host memory over time, ultimately leading to termination by the OOM killer and rendering containerd unavailable until it is restarted.
We recommend you to update containerd to version 2.3.5 or 2.2.8 or 2.0.12 or 1.7.35.[/subscribe_to_unlock_form]
A medium severity vulnerability, identified as CVE-2026-53495 with a CVSS v4 score of 6.8, exists in containerd's CRI ExecSync implementation that allows exec probes and lifecycle hooks with background child processes to indefinitely block containerd's stdio-drain goroutines leading to resource exhaustion and potential node-level denial of service on Linux systems running containerd with the CRI plugin enabled. This flaw is exploitable via the CRI plugin, requiring low privileges for an attacker to launch long-lived background child processes against a container. The affected versions include those prior to 2.0.12, 1.7.35, and between 2.2.0 and 2.2.8, as well as 2.3.0 and 2.3.5. Users not utilizing the CRI implementation or running containers on Linux are unaffected. This issue can cause containerd to leak goroutines and host memory over time, ultimately leading to termination by the OOM killer and rendering containerd unavailable until it is restarted.
We recommend you to update containerd to version 2.3.5 or 2.2.8 or 2.0.12 or 1.7.35.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]