CVE-2024-40635

CVSS 3.1 Score 4.6 of 10 (medium)

Details

Published Mar 17, 2025
CWE ID 190

Summary

CVE-2024-40635 is a vulnerability in containerd, an open-source container runtime, affecting versions prior to 1.6.38, 1.7.27, and 2.0.4. This issue allows containers to be launched with a User set as a UID:GID larger than the maximum 32-bit signed integer, resulting in an overflow condition. The container ultimately runs as root (UID 0), which can lead to unexpected behaviors in environments requiring containers to run as a non-root user. The vulnerability has been addressed in containerd versions 1.6.38, 1.7.27, and 2.0.4. As a temporary measure, it's recommended to use only trusted images and to grant import permissions only to trusted users.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • containerd

Affected Vendors

  • Cloud Native Computing Foundation