CVE-2025-64329

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-64329
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-64329.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-64329
Aliases
Downstream
Related
Published
2025-11-07T04:15:09Z
Modified
2025-11-11T02:56:13.205311Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
containerd CRI server: Host memory exhaustion through Attach goroutine leak
Details

containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4, and 2.2.0-beta.0 through 2.2.0-rc.1 contain a bug in the CRI Attach implementation where a user can exhaust memory on the host due to goroutine leaks. This issue is fixed in versions 1.7.29, 2.0.7, 2.1.5 and 2.2.0. To workaround this vulnerability, users can set up an admission controller to control accesses to pods/attach resources.

Database specific
{
    "cwe_ids": [
        "CWE-401"
    ]
}
References

Affected packages

Git / github.com/containerd/containerd

Affected ranges

Type
GIT
Repo
https://github.com/containerd/containerd
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*

0.0.2
0.0.3
0.0.4
0.0.5

api/v1.*

api/v1.10.0
api/v1.10.0-beta.0
api/v1.10.0-beta.1
api/v1.10.0-rc.0
api/v1.6.0-beta.1
api/v1.6.0-beta.2
api/v1.6.0-beta.3
api/v1.8.0
api/v1.8.0-rc.0
api/v1.8.0-rc.1
api/v1.8.0-rc.2
api/v1.8.0-rc.3
api/v1.8.0-rc.4
api/v1.9.0
api/v1.9.0-rc.0

v0.*

v0.1.0
v0.2.0
v0.2.3

v1.*

v1.0.0
v1.0.0-alpha0
v1.0.0-alpha1
v1.0.0-alpha2
v1.0.0-alpha3
v1.0.0-alpha4
v1.0.0-alpha5
v1.0.0-alpha6
v1.0.0-beta.0
v1.0.0-beta.1
v1.0.0-beta.2
v1.0.0-beta.3
v1.0.0-rc.0
v1.1.0
v1.1.0-rc.0
v1.1.0-rc.1
v1.1.0-rc.2
v1.2.0
v1.2.0-beta.0
v1.2.0-beta.1
v1.2.0-beta.2
v1.2.0-rc.0
v1.2.0-rc.1
v1.2.0-rc.2
v1.3.0
v1.3.0-beta.0
v1.3.0-beta.1
v1.3.0-beta.2
v1.3.0-rc.0
v1.3.0-rc.1
v1.3.0-rc.2
v1.3.0-rc.3
v1.4.0
v1.4.0-beta.0
v1.4.0-beta.1
v1.4.0-beta.2
v1.4.0-rc.0
v1.4.0-rc.1
v1.5.0
v1.5.0-beta.0
v1.5.0-beta.1
v1.5.0-beta.2
v1.5.0-beta.3
v1.5.0-beta.4
v1.5.0-rc.0
v1.5.0-rc.1
v1.5.0-rc.2
v1.5.0-rc.3
v1.6.0
v1.6.0-beta.0
v1.6.0-beta.1
v1.6.0-beta.2
v1.6.0-beta.3
v1.6.0-beta.4
v1.6.0-beta.5
v1.6.0-rc.0
v1.6.0-rc.1
v1.6.0-rc.2
v1.6.0-rc.3
v1.6.0-rc.4
v1.7.0
v1.7.0-beta.0
v1.7.0-beta.1
v1.7.0-beta.2
v1.7.0-beta.3
v1.7.0-beta.4
v1.7.0-rc.0
v1.7.0-rc.1
v1.7.0-rc.2
v1.7.0-rc.3

v2.*

v2.0.0
v2.0.0-beta.0
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-rc.0
v2.0.0-rc.1
v2.0.0-rc.2
v2.0.0-rc.3
v2.0.0-rc.4
v2.0.0-rc.5
v2.0.0-rc.6
v2.1.0
v2.1.0-beta.0
v2.1.0-beta.1
v2.1.0-rc.0
v2.1.0-rc.1
v2.2.0-beta.0
v2.2.0-beta.1
v2.2.0-beta.2
v2.2.0-rc.0
v2.2.0-rc.1