CVE-2024-40635
CVSS 3.1 Score 4.6 of 10 (medium)
Details
Summary
CVE-2024-40635 is a vulnerability in containerd, an open-source container runtime, affecting versions prior to 1.6.38, 1.7.27, and 2.0.4. This issue allows containers to be launched with a User set as a UID:GID larger than the maximum 32-bit signed integer, resulting in an overflow condition. The container ultimately runs as root (UID 0), which can lead to unexpected behaviors in environments requiring containers to run as a non-root user. The vulnerability has been addressed in containerd versions 1.6.38, 1.7.27, and 2.0.4. As a temporary measure, it's recommended to use only trusted images and to grant import permissions only to trusted users.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- containerd
Affected Vendors
- Cloud Native Computing Foundation