🛡️ CVE-2022-31030
🟡 CVSS 5.5 — Medium ✅ No Known Exploit CWE-400 NVD
5.5
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

containerd is an open source container runtime. A bug was found in the containerd's CRI implementation where programs inside a container can cause the containerd daemon to consume memory without bound during invocation of the `ExecSync` API. This can cause containerd to consume all available memory on the computer, denying service to other legitimate workloads. Kubernetes and crictl can both be configured to use containerd's CRI implementation; `ExecSync` may be used when running probes or when executing processes via an "exec" facility. This bug has been fixed in containerd 1.6.6 and 1.5.13. Users should update to these versions to resolve the issue. Users unable to upgrade should ensure that only trusted images and commands are used.

Details

Severity MEDIUM
CVSS Score 5.5
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE CWE-400
Public Exploit ✅ No
Source NVD
Published 2022-06-09
Updated 2026-06-15
Modified 2024-11-21
Fix URL N/A

Affected Packages

Software From version Fixed in
containerd 1.6.0 1.6.6
debian-linux
fedora
github.com/containerd/containerd

References

Mailing List, Third Party Advisory http://www.openwall.com/lists/oss-security/2022/06/07/1
Mailing List, Third Party Advisory http://www.openwall.com/lists/oss-security/2022/06/07/1

Free Vulnerability Check

Is your WordPress site affected?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.