CRITICAL9.9CVE-2026-50195containerd: CRI checkpoint import allows local image tag poisoning in github.com/containerd/containerd from 0, < 2.1.9+ds1-1
CRITICAL9.6CVE-2026-53492containerd CRI checkpoint restore CDI annotation smuggling in github.com/containerd/containerd from 0, < 2.1.9+ds1-1
HIGH8.8CVE-2026-53488containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull in github.com/containerd/containerd from 0
HIGH7.8containerd user ID handling bypass allows runAsNonRoot evasion in github.com/containerd/containerd
from 0
HIGH7.5containerd - security update
from 0, < 1.4.13~ds1-1~deb11u1
HIGH7.5containerd - security update
from 0, < 1.4.13~ds1-1~deb11u1
HIGH7.3containerd - security update
from 0, < 1.4.13~ds1-1~deb11u6
HIGH7.3containerd - security update
from 0, < 1.4.13~ds1-1~deb11u6
HIGH7.3containerd - security update
from 0, < 1.6.20~ds1-1+deb12u2
MEDIUM6.5Arbitrary host CRI log file read via symlink following in CRI checkpoint restore in github.com/containerd/containerd
from 0, < 2.1.9+ds1-1
MEDIUM6.1docker.io - security update
from 0, < 1.3.2~ds1-2
MEDIUM5.9containerd - security update
from 0, < 1.4.13~ds1-1~deb11u2
MEDIUM5.9containerd - security update
from 0, < 1.4.13~ds1-1~deb11u2
MEDIUM5.7containerd CRI stream server vulnerable to host memory exhaustion via terminal in github.com/containerd/containerd
from 0, < 1.4.13~ds1-1~deb11u3
MEDIUM5.5containerd image-triggered runtime DoS via unbounded group parsing in github.com/containerd/containerd
from 0
MEDIUM5.5containerd CRI server: Host memory exhaustion through Attach goroutine leak in github.com/containerd/containerd
from 0, < 1.4.13~ds1-1~deb11u6
MEDIUM5.5Memory exhaustion via OCI image importer in github.com/containerd/containerd
from 0, < 1.4.13~ds1-1~deb11u4
MEDIUM5.5containerd CRI plugin: Host memory exhaustion through ExecSync in github.com/containerd/containerd
from 0, < 1.4.13~ds1-1~deb11u2
MEDIUM5.3Privilege escalation via supplementary groups in github.com/containerd/containerd
from 0, < 1.4.13~ds1-1~deb11u4
MEDIUM5.2containerd-shim API Exposed to Host Network Containers in github.com/containerd/containerd
from 0, < 1.4.3~ds1-1
MEDIUM4.6containerd - security update
from 0, < 1.4.13~ds1-1~deb11u5
MEDIUM4.6containerd - security update
from 0, < 1.4.13~ds1-1~deb11u5