{"schema_version":"1.7.3","id":"GHSA-crp2-qrr5-8pq7","published":"2022-03-02T21:33:17Z","modified":"2026-02-04T03:54:49.966557Z","aliases":["CVE-2022-23648","GO-2022-0344"],"related":["CGA-9w43-prw2-8w2j"],"summary":"containerd CRI plugin: Insecure handling of image volumes","details":"### Impact\n\nA bug was found in containerd where containers launched through containerd’s CRI implementation with a specially-crafted image configuration could gain access to read-only copies of arbitrary files and directories on the host.  This may bypass any policy-based enforcement on container setup (including a Kubernetes Pod Security Policy) and expose potentially sensitive information.  Kubernetes and crictl can both be configured to use containerd’s CRI implementation.\n\n### Patches\n\nThis bug has been fixed in containerd 1.6.1, 1.5.10 and 1.4.13.  Users should update to these versions to resolve the issue.\n\n### Workarounds\n\nEnsure that only trusted images are used.\n\n### Credits\n\nThe containerd project would like to thank Felix Wilhelm of Google Project Zero for responsibly disclosing this issue in accordance with the [containerd security policy](https://github.com/containerd/project/blob/main/SECURITY.md).\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n* Open an issue in [containerd](https://github.com/containerd/containerd/issues/new/choose)\n* Email us at [security@containerd.io](mailto:security@containerd.io)","affected":[{"package":{"name":"github.com/containerd/containerd","ecosystem":"Go","purl":"pkg:golang/github.com/containerd/containerd"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.4.13"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-crp2-qrr5-8pq7/GHSA-crp2-qrr5-8pq7.json"}},{"package":{"name":"github.com/containerd/containerd","ecosystem":"Go","purl":"pkg:golang/github.com/containerd/containerd"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.5.0"},{"fixed":"1.5.10"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-crp2-qrr5-8pq7/GHSA-crp2-qrr5-8pq7.json"}},{"package":{"name":"github.com/containerd/containerd","ecosystem":"Go","purl":"pkg:golang/github.com/containerd/containerd"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.6.0"},{"fixed":"1.6.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-crp2-qrr5-8pq7/GHSA-crp2-qrr5-8pq7.json"}}],"references":[{"type":"WEB","url":"https://github.com/containerd/containerd/security/advisories/GHSA-crp2-qrr5-8pq7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23648"},{"type":"WEB","url":"https://github.com/containerd/containerd/commit/10f428dac7cec44c864e1b830a4623af27a9fc70"},{"type":"PACKAGE","url":"https://github.com/containerd/containerd"},{"type":"WEB","url":"https://github.com/containerd/containerd/releases/tag/v1.4.13"},{"type":"WEB","url":"https://github.com/containerd/containerd/releases/tag/v1.5.10"},{"type":"WEB","url":"https://github.com/containerd/containerd/releases/tag/v1.6.1"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AUDQUQBZJGBWJPMRVB6QCCCRF7O3O4PA"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HFTS2EF3S7HNYSNZSEJZIJHPRU7OPUV3"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OCCARJ6FU4MWBTXHZNMS7NELPDBIX2VO"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AUDQUQBZJGBWJPMRVB6QCCCRF7O3O4PA"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HFTS2EF3S7HNYSNZSEJZIJHPRU7OPUV3"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OCCARJ6FU4MWBTXHZNMS7NELPDBIX2VO"},{"type":"WEB","url":"https://security.gentoo.org/glsa/202401-31"},{"type":"WEB","url":"https://www.debian.org/security/2022/dsa-5091"},{"type":"WEB","url":"http://packetstormsecurity.com/files/166421/containerd-Image-Volume-Insecure-Handling.html"}],"database_specific":{"cwe_ids":["CWE-200"],"github_reviewed":true,"github_reviewed_at":"2022-03-02T21:33:17Z","nvd_published_at":"2022-03-03T14:15:00Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}