CVE-2023-25153

Aliases:GHSA-259w-8hf6-59c2GO-2023-1573
Modified
Published: 16 Feb 2023, 14:09
Last modified:10 Mar 2025, 21:10

Vulnerability Summary

Overall Risk (default)
medium
25/100
CVSS Score
6.2 MEDIUM
v3.1 (cve.org)
EPSS Score
0.24% LOW
0% probability +0.12%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

16 Feb 2023, 14:09
Published
Vulnerability first disclosed
10 Mar 2025, 21:10
Last Modified
Vulnerability information updated

Description

containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file where a limit was not applied could cause a denial of service. This bug has been fixed in containerd 1.6.18 and 1.5.18. Users should update to these versions to resolve the issue. As a workaround, ensure that only trusted images are used and that only trusted users have permissions to import images.

CVSS Metrics

  • v3.1MEDIUMScore: 6.2CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.24% Percentile: 48%

Techniques & Countermeasures

  • CWE-770Allocation of Resources Without Limits or Throttling

    The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Affected Systems

  • containerdcontainerd

    < 1.5.18 | ≥ 1.6.0, < 1.6.18

  • github.com/containerdcontainerd

    < 1.5.18 | ≥ 1.6.0, < 1.6.18

  • linuxfoundationcontainerd

    < 1.5.18 | ≥ 1.6.0, < 1.6.18

References (7)