Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-47290


containerd is a container runtime. A time-of-check to time-of-use (TOCTOU) vulnerability was found in containerd v2.1.0. While unpacking an image during an image pull, specially crafted container images could arbitrarily modify the host file system. The only affected version of containerd is 2.1.0. Other versions of containerd are not affected. This bug has been fixed in containerd 2.1.1. Users should update to this version to resolve the issue. As a workaround, ensure that only trusted images are used and that only trusted users have permissions to import images.


Published

2025-05-20T19:15:50.157

Last Modified

2025-09-19T17:28:20.350

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-367

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application linuxfoundation containerd 2.1.0 Yes

References