{"schema_version":"1.7.5","id":"openSUSE-SU-2026:21213-1","published":"2026-07-02T09:47:31Z","modified":"2026-07-03T11:00:06.792601975Z","related":["CVE-2024-25621","CVE-2025-64329","CVE-2026-33186","CVE-2026-33814","CVE-2026-34986","CVE-2026-35469","CVE-2026-39821","CVE-2026-46680","CVE-2026-47262","CVE-2026-53488"],"upstream":["CVE-2024-25621","CVE-2025-64329","CVE-2026-33186","CVE-2026-33814","CVE-2026-34986","CVE-2026-35469","CVE-2026-39821","CVE-2026-46680","CVE-2026-47262","CVE-2026-53488"],"summary":"Security update for containerd","details":"This update for containerd fixes the following issues\n\nUpdate to 1.7.33:\n\n- CVE-2024-25621: overly broad default permission vulnerability (bsc#1253126).\n- CVE-2025-64329: goroutine leaks can lead to memory exhaustion on the host (bsc#1253132).\n- CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo-\n  header (bsc#1260296).\n- CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE\n  (bsc#1265794).\n- CVE-2026-34986: github.com/go-jose/go-jose/v4,github.com/go-jose/go-jose/v3: crafted JWE input with a missing\n  encrypted key can lead to a denial of service (bsc#1262948).\n- CVE-2026-35469: github.com/moby/spdystream: memory amplification in SPDY frame parsing leads to denial of service\n  (bsc#1262266).\n- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation\n  bypass and privilege escalation (bsc#1266640).\n- CVE-2026-46680: containerd user ID handling bypass allows runAsNonRoot evasion (bsc#1268355).\n- CVE-2026-47262: Denial of Service (DoS) condition via a maliciously crafted image (bsc#1268441).\n- CVE-2026-53488: CRI plugin propagates labels from an image config to a container without validation (bsc#1268430).\n\nChanges for containerd:\n\n * https://github.com/containerd/containerd/releases/tag/v1.7.33\n * https://github.com/containerd/containerd/releases/tag/v1.7.32\n * https://github.com/containerd/containerd/releases/tag/v1.7.31\n * https://github.com/containerd/containerd/releases/tag/v1.7.30\n * https://github.com/containerd/containerd/releases/tag/v1.7.29\n * https://github.com/containerd/containerd/releases/tag/v1.7.28\n","affected":[{"package":{"name":"containerd","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/containerd&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.7.33-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"containerd":"1.7.33-160000.1.1","containerd-ctr":"1.7.33-160000.1.1","containerd-devel":"1.7.33-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21213-1.json"}}],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1253126"},{"type":"REPORT","url":"https://bugzilla.suse.com/1253132"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260296"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262266"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262948"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265794"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266640"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268355"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268430"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268441"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-25621"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-64329"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33186"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33814"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34986"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-35469"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39821"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46680"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-47262"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53488"}]}