CVE-2025-64329
containerd CRI server: Host memory exhaustion through Attach goroutine leak in github.com/containerd/containerd
5.5
MEDIUM
CVSS 3.1
EPSS 0.16%
描述
containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4, and 2.2.0-beta.0 through 2.2.0-rc.1 contain a bug in the CRI Attach implementation where a user can exhaust memory on the host due to goroutine leaks. This issue is fixed in versions 1.7.29, 2.0.7, 2.1.5 and 2.2.0. To workaround this vulnerability, users can set up an admission controller to control accesses to pods/attach resources.
如何修補 CVE-2025-64329
要修補 CVE-2025-64329,請將受影響套件升級到下列已修補版本。
- —升級至 1.4.13~ds1-1~deb11u6 或更新版本
- —升級至 1.7.29 或更新版本
- —升級至 1.7.29 或更新版本
- —升級至 2.0.7 或更新版本
- —升級至 2.0.7 或更新版本
CVE-2025-64329 正在被利用嗎?
低 — EPSS 為 0.2%,目前沒有觀察到大規模利用活動。
受影響套件(5)
- from 0, < 1.4.13~ds1-1~deb11u6
- from 0, < 1.7.29
- from 0, < 1.7.29
- from 0, < 2.0.7
- from 0, < 2.0.7, >= 2.1.0-beta.0, < 2.1.5, >= 2.2.0-beta.0, < 2.2.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | MEDIUM5.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |