Skip to content

containerd CVE-2023-25153

Moderate
rpkelly published GHSA-pp3v-5483-gc93 Mar 21, 2023

Package

containerd (bottlerocket)

Affected versions

< 1.13.0

Patched versions

1.13.0

Description

When importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file where a limit was not applied could cause a denial of service.

Severity

Moderate

CVE ID

CVE-2023-25153

Weaknesses

No CWEs