Threat Advisory

Containerd Flaw Causes Unbounded CPU and Memory Consumption

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-53493 with a CVSS score of 6.9 is a medium-severity vulnerability in containerd's image pull handlers where a crafted OCI image index containing deeply nested or heavily fanned-out descriptor graphs can cause unbounded CPU and memory consumption during the PullImage operation, leading to prolonged stalls during container creation and significant resource pressure on the host system. This issue occurs entirely during the image pull phase, prior to any container execution, in versions of containerd greater than or equal to 2.0.0 and less than 2.0.13, as well as in versions less than or equal to 1.7.35, and also in versions greater than or equal to 2.1.0 and less than 2.2.9, and greater than or equal to 2.3.0 and less than 2.3.6, and version 2.4.0.

RECOMMENDATION:

We recommend you to update containerd to version 1.7.36 or 2.0.13, 2.2.9, 2.3.6, or 2.4.1 depending on your installed branch.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-53493 with a CVSS score of 6.9 is a medium-severity vulnerability in containerd's image pull handlers where a crafted OCI image index containing deeply nested or heavily fanned-out descriptor graphs can cause unbounded CPU and memory consumption during the PullImage operation, leading to prolonged stalls during container creation and significant resource pressure on the host system. This issue occurs entirely during the image pull phase, prior to any container execution, in versions of containerd greater than or equal to 2.0.0 and less than 2.0.13, as well as in versions less than or equal to 1.7.35, and also in versions greater than or equal to 2.1.0 and less than 2.2.9, and greater than or equal to 2.3.0 and less than 2.3.6, and version 2.4.0.

RECOMMENDATION:

We recommend you to update containerd to version 1.7.36 or 2.0.13, 2.2.9, 2.3.6, or 2.4.1 depending on your installed branch.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu