DEBIAN-CVE-2026-53488

Source
https://security-tracker.debian.org/tracker/CVE-2026-53488
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-53488.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2026-53488
Upstream
Published
2026-07-01T02:17:00Z
Modified
2026-09-01T16:06:50Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.

References

Affected packages

Debian:12 / containerd

Package

Name
containerd
Purl
pkg:deb/debian/containerd?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.6.20~ds1-1
1.6.20~ds1-1+deb12u1
1.6.20~ds1-1+deb12u2
1.6.20~ds1-1+deb12u3
1.6.20~ds1-2
1.6.24~ds1-1
1.6.24~ds1-2
1.7.18~ds1-1
1.7.18~ds1-2
1.7.18~ds1-3
1.7.18~ds1-4
1.7.18~ds1-5
1.7.18~ds1-6
1.7.18~ds2-1
1.7.20~ds2-1
1.7.20~ds2-2
1.7.21~ds2-1
1.7.22~ds1-1
1.7.23~ds1-1
1.7.23~ds1-2
1.7.23~ds1-3
1.7.23~ds2-1
1.7.24~ds1-1
1.7.24~ds1-2
1.7.24~ds1-3
1.7.24~ds1-4
1.7.24~ds1-5
1.7.24~ds1-6
1.7.24~ds1-7
1.7.24~ds1-8
1.7.24~ds1-9
1.7.24~ds1-10
2.*
2.1.4~ds2-2
2.1.4~ds2-3
2.1.4~ds2-4
2.1.4~ds2-5
2.1.4~ds2-6
2.1.4~ds2-7
2.1.4~ds2-8
2.1.6+ds1-1
2.1.9+ds1-1
2.1.9+ds1-2

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-53488.json"

Debian:13 / containerd

Package

Name
containerd
Purl
pkg:deb/debian/containerd?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.7.24~ds1-6
1.7.24~ds1-6+deb13u1
1.7.24~ds1-7
1.7.24~ds1-8
1.7.24~ds1-9
1.7.24~ds1-10
2.*
2.1.4~ds2-2
2.1.4~ds2-3
2.1.4~ds2-4
2.1.4~ds2-5
2.1.4~ds2-6
2.1.4~ds2-7
2.1.4~ds2-8
2.1.6+ds1-1
2.1.9+ds1-1
2.1.9+ds1-2

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-53488.json"

Debian:14 / containerd

Package

Name
containerd
Purl
pkg:deb/debian/containerd?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.1.9+ds1-1

Affected versions

1.*
1.7.24~ds1-6
1.7.24~ds1-7
1.7.24~ds1-8
1.7.24~ds1-9
1.7.24~ds1-10
2.*
2.1.4~ds2-2
2.1.4~ds2-3
2.1.4~ds2-4
2.1.4~ds2-5
2.1.4~ds2-6
2.1.4~ds2-7
2.1.4~ds2-8
2.1.6+ds1-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-53488.json"