containerd is a container runtime. A time-of-check to time-of-use (TOCTOU) vulnerability was found in containerd v2.1.0. While unpacking an image during an image pull, specially crafted container images could arbitrarily modify the host file system. The only affected version of containerd is 2.1.0. Other versions of containerd are not affected. This bug has been fixed in containerd 2.1.1. Users should update to this version to resolve the issue. As a workaround, ensure that only trusted images are used and that only trusted users have permissions to import images.
History

Sat, 31 May 2025 03:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H'}

threat_severity

Important


Tue, 20 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 20 May 2025 18:45:00 +0000

Type Values Removed Values Added
Description containerd is a container runtime. A time-of-check to time-of-use (TOCTOU) vulnerability was found in containerd v2.1.0. While unpacking an image during an image pull, specially crafted container images could arbitrarily modify the host file system. The only affected version of containerd is 2.1.0. Other versions of containerd are not affected. This bug has been fixed in containerd 2.1.1. Users should update to this version to resolve the issue. As a workaround, ensure that only trusted images are used and that only trusted users have permissions to import images.
Title Containerd vulnerable to host filesystem access during image unpack
Weaknesses CWE-367
References
Metrics cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-05-20T18:25:51.703Z

Updated: 2025-05-20T18:44:19.248Z

Reserved: 2025-05-05T16:53:10.374Z

Link: CVE-2025-47290

cve-icon Vulnrichment

Updated: 2025-05-20T18:43:25.797Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-20T19:15:50.157

Modified: 2025-05-21T20:24:58.133

Link: CVE-2025-47290

cve-icon Redhat

Severity : Important

Publid Date: 2025-05-20T18:25:51Z

Links: CVE-2025-47290 - Bugzilla